SCA: security update for indico (GHSA-fmqq-25x9-c6hm)

medium Tenable Self-Hosted Container Security Plugin ID 414591

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-
Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico.
Exploitation requires someone with at least submission privileges (such as a speaker) and then someone
else to attempt to delete this content. Considering that event organizers may want to delete suspicious-
looking content when spotting it, there is a non-negligible risk of such an attack to succeed. The risk of
this could be further increased when combined with some some social engineering pointing the victim
towards this content. Users need to update to Indico 3.2.6 as soon as possible. See the docs for
instructions on how to update. Users who cannot upgrade should only let trustworthy users manage
categories, create events or upload materials ("submission" privileges on a contribution/event). This
should already be the case in a properly-configured setup when it comes to category/event management. Note
that a conference doing a Call for Abstracts actively invites external speakers (who the organizers may
not know and thus cannot fully trust) to submit content, hence the need to update to a a fixed version
ASAP in particular when using such workflows. (CVE-2023-37901)

See Also

https://github.com/advisories/GHSA-fmqq-25x9-c6hm

Plugin Details

Severity: Medium

ID: 414591

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.14

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2023-37901

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/21/2023

Vulnerability Publication Date: 7/21/2023

Reference Information

CVE: CVE-2023-37901

cwe: CWE-79