CVE-2024-50633

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 16, 2025
Updated: Jan 17, 2025
CWE ID 862

Summary

CVE-2024-50633 is a Broken Object Level Authorization (BOLA) vulnerability affecting Indico v3.2.9. This issue enables attackers to gain unauthorized access to sensitive information by sending a skillfully crafted POST request to the /api/principals component. The vulnerability can potentially lead to data breaches and unintended system modifications, making it a significant security concern for organizations using Indico version 3.2.9. Attackers can exploit this weakness without requiring any user privileges or authentication, increasing the risk of data exposure. Users are recommended to update to the latest version of Indico to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share