Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27579 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).
Github GHSA Github GHSA GHSA-4269-mcfh-cp7q Indico may disclose unauthorized user details access via legacy API
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cern:indico:*:*:*:*:*:*:*:*

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Cern
Cern indico
Vendors & Products Cern
Cern indico

Thu, 11 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Description Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).
Title Indico may disclose unauthorized user details access via legacy API
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-11T14:42:53.468Z

Reserved: 2025-09-08T16:19:26.170Z

Link: CVE-2025-59034

cve-icon Vulnrichment

Updated: 2025-09-11T14:27:13.197Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-10T16:15:41.130

Modified: 2025-09-17T21:31:06.693

Link: CVE-2025-59034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-12T09:11:32Z