SCA: security update for indico (GHSA-q28v-664f-q6wj)

medium Tenable Self-Hosted Container Security Plugin ID 428381

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for
Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users
listed in certain fields (such as ACLs) could be misused to dump basic user details (such as name,
affiliation and email) in bulk. Version 3.3.7 fixes the issue. Owners of instances that allow everyone to
create a user account, who wish to truly restrict access to these user details, should consider
restricting user search to managers. As a workaround, it is possible to restrict access to the affected
endpoints (e.g. in the webserver config), but doing so would break certain form fields which could no
longer show the details of the users listed in those fields, so upgrading instead is highly recommended.
(CVE-2025-53640)

See Also

https://github.com/advisories/GHSA-q28v-664f-q6wj

Plugin Details

Severity: Medium

ID: 428381

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 7/15/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2025-53640

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 2.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/14/2025

Vulnerability Publication Date: 7/14/2025

Reference Information

CVE: CVE-2025-53640