GHSA-cw24-x4mj-fw3q: XSS
Impact There is a Cross-Site-Scripting vulnerability in the minute editor conflict UI tha's shown when concurrent edits are made to the same minutes in an event.
Patches You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
Workarounds - Set CSPENABLED = True in indico.conf - this is recommended regardless of updating. - Only let trustworthy users create content (including minutes which speakers can typically do as well) on Indico.
For more information If you have any questions or comments about this advisory:
- Open a thread in our forum - Email us privately at indico-team@cern.ch
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Upgrade
Upgrade
Indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Configuration
Set CSP_ENABLED = True in indico.conf.
Indico CSP_ENABLED = True - Compensating control
Only let trustworthy users create content in Indico, including minutes that speakers can typically edit.
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a user who can create content in Indico, including minutes. Speakers can typically create minutes, so access should be limited to trustworthy users.
When is the vulnerable interface exposed?
The issue is in the minute editor conflict UI, which is shown when concurrent edits are made to the same minutes in an event. An attacker would need to trigger or participate in that concurrent-edit scenario and induce a victim to interact with the affected UI.
What should be done if upgrading cannot happen immediately?
Set CSP_ENABLED = True in indico.conf and restrict content-creation permissions to trusted users. The advisory recommends enabling CSP regardless of whether the software is updated.
What version should be deployed to remediate the issue?
Update Indico to version 3.3.13 as soon as possible.