GHSA-c4wc-ggrj-jg9v: Medium severity pip/indico vulnerability
Impact There is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.
Patches You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
Workarounds - Set CSPENABLED = True in indico.conf - this is recommended regardless of updating. - Only let trustworthy users manage events or create content (including material uploads which speakers can typically do as well) on Indico.
For more information If you have any questions or comments about this advisory:
- Open a thread in our forum - Email us privately at indico-team@cern.ch
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Upgrade
Upgrade
Indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Configuration
Set CSP_ENABLED = True in indico.conf; this is recommended regardless of updating.
Indico CSP_ENABLED = True - Compensating control
Only let trustworthy users manage events or create content, including material uploads, on Indico.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permissions to enter custom URLs in Indico content fields. Users who can manage events, create content, or upload materials, including speakers where they are allowed to upload materials, may have relevant access.
What should be done to remediate the issue?
Update Indico to version 3.3.13 as soon as possible. Enable CSP by setting CSP_ENABLED = True in indico.conf; this is recommended even after updating.
What can reduce risk if an update cannot be applied immediately?
Enable CSP_ENABLED = True in indico.conf and restrict event-management, content-creation, and material-upload permissions to trustworthy users. This limits the users who can provide malicious custom URLs.