PT-2025-2876 · Indico · Indico

Thiefmaster

·

Published

2025-01-10

·

Updated

2025-01-21

·

CVE-2024-50633

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Indico versions 3.2.9 through 3.3.5
Description A Broken Object Level Authorization (BOLA) issue allows attackers to read or access sensitive information by sending a crafted POST request to the "/api/principals" component. The supplier disputes this issue, stating that the product is designed to allow all users to retrieve certain information about other user accounts.
Recommendations For Indico versions 3.2.9 through 3.3.5, as a temporary workaround, consider restricting access to the "/api/principals" component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50633
GHSA-3WG7-R7Q5-R2JF

Affected Products

Indico