CVE-2024-50633

NONE
Published Jan 16, 2025 Modified Sep 19, 2025 CWE-201

Description

A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).

Is your site exposed to CVE-2024-50633?

Run a free security scan — no signup, results in seconds.

Weakness Type (CWE)

CWE-201 CWE-201

Affected Products

Vendor Product
cern indico

References

Frequently Asked Questions

What is CVE-2024-50633? +
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).
What products are affected by CVE-2024-50633? +
CVE-2024-50633 affects products from cern, specifically: indico. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-50633? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-50633 — free, no signup required.