A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).
History

Tue, 18 Feb 2025 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Tue, 21 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}


Tue, 21 Jan 2025 14:30:00 +0000

Type Values Removed Values Added
Description A Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9 allows attackers to access sensitive information via sending a crafted POST request to the component /api/principals. A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).
References

Fri, 17 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description A Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9 allows attackers to access sensitive information via sending a crafted POST request to the component /api/principals.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-18T21:00:48.454Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-50633

cve-icon Vulnrichment

Updated: 2025-01-17T17:25:15.412Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-16T18:15:24.337

Modified: 2025-02-18T21:15:22.343

Link: CVE-2024-50633

cve-icon Redhat

No data.