VYPR
None severity0.0NVD Advisory· Published Jan 16, 2025· Updated Jun 17, 2026

CVE-2024-50633

CVE-2024-50633

Description

A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
indicoPyPI
>= 3.2.9, < 3.3.33.3.3

Affected products

3
  • Cern/Indico2 versions
    cpe:2.3:a:cern:indico:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cern:indico:*:*:*:*:*:*:*:*range: >=3.2.9,<=3.3.2
    • (no CPE)range: 2.2
  • ghsa-coords
    Range: >= 3.2.9, < 3.3.3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.