CVE-2025-59034: Indico may disclose unauthorized user details access via legacy API

Published Sep 10, 2025
·
Updated

Impact A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.

Patches You should to update to Indico 3.3.8 as soon as possible. See the docs for instructions on how to update.

Workarounds It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.

For more information If you have any questions or comments about this advisory:

- Open a thread in our forum - Email us privately at indico-team@cern.ch

Other sources

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).

— MITRE

Affected Software

4 affected componentsFixes available
Indico Indico<3.3.8
Flask-Multipass Flask-Multipass<3.3.8
pip/indico<=3.3.7
3.3.8
cern Indico<3.3.8

Event History

Sep 10, 2025
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·08:27 PM
Data Sourced
via GitHub·08:27 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59034?

CVE-2025-59034 has a moderate severity level due to the potential exposure of user profile details without proper permissions.

2

How do I fix CVE-2025-59034?

To fix CVE-2025-59034, upgrade to Indico or Flask-Multipass version 3.3.8 or later.

3

What impact does CVE-2025-59034 have on my application?

CVE-2025-59034 allows unauthorized users to access other users' profile information, potentially compromising user privacy.

4

Which versions are affected by CVE-2025-59034?

CVE-2025-59034 affects versions of Indico and Flask-Multipass prior to 3.3.8.

5

Is CVE-2025-59034 a code injection vulnerability?

No, CVE-2025-59034 is not a code injection vulnerability; it relates to improper access controls in the legacy API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203