CVE-2025-59034: Indico may disclose unauthorized user details access via legacy API
Impact A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.
Patches You should to update to Indico 3.3.8 as soon as possible. See the docs for instructions on how to update.
Workarounds It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.
For more information If you have any questions or comments about this advisory:
- Open a thread in our forum - Email us privately at indico-team@cern.ch
Other sources
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59034?
CVE-2025-59034 has a moderate severity level due to the potential exposure of user profile details without proper permissions.
How do I fix CVE-2025-59034?
To fix CVE-2025-59034, upgrade to Indico or Flask-Multipass version 3.3.8 or later.
What impact does CVE-2025-59034 have on my application?
CVE-2025-59034 allows unauthorized users to access other users' profile information, potentially compromising user privacy.
Which versions are affected by CVE-2025-59034?
CVE-2025-59034 affects versions of Indico and Flask-Multipass prior to 3.3.8.
Is CVE-2025-59034 a code injection vulnerability?
No, CVE-2025-59034 is not a code injection vulnerability; it relates to improper access controls in the legacy API.