Skip to main content

Insertion of Sensitive Information Into Sent Data

CVE-2024-50633

Severity Medium
Score 6.9/10

Summary

A Broken Object Level Authorization (BOLA) vulnerability in Indico versions through 3.3.2 allows attackers to access sensitive information via sending a crafted POST request to the component '/api/principals'.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-201 - Insertion of Sensitive Information Into Sent Data

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Advisory Timeline

  • Published