{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-13T16:39:29.369","vulnerabilities":[{"cve":{"id":"CVE-2025-59034","sourceIdentifier":"security-advisories@github.com","published":"2025-09-10T16:15:41.130","lastModified":"2025-09-17T21:31:06.693","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config)."},{"lang":"es","value":"Indico es un sistema de gestión de eventos que utiliza Flask-Multipass, un sistema de autenticación multi-backend para Flask. Antes de la versión 3.3.8, una API heredada para recuperar detalles de usuario podría ser mal utilizada para recuperar detalles de perfil de otros usuarios sin tener permisos de administrador debido a una verificación de acceso defectuosa. Los usuarios deberían actualizar a Indico 3.3.8 lo antes posible. Como solución alternativa, es posible restringir el acceso a la API afectada (por ejemplo, en la configuración del servidor web)."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cern:indico:*:*:*:*:*:*:*:*","versionEndExcluding":"3.3.8","matchCriteriaId":"9763A025-1F04-491A-AA56-DE5C785E7D05"}]}]}],"references":[{"url":"https://github.com/indico/indico/releases/tag/v3.3.8","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/indico/indico/security/advisories/GHSA-4269-mcfh-cp7q","source":"security-advisories@github.com","tags":["Patch","Vendor Advisory"]}]}}]}