{"id":"CVE-2024-50633","aliases":["GHSA-3wg7-r7q5-r2jf","PYSEC-2026-1459"],"title":"Indico Insecure Access","summary":"Indico Insecure Access","severity":"none","cvss":0,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","vendor":"indico","product":"indico","ecosystem":"pip","affected":["indico >= 3.2.9, < 3.3.3"],"patched":["indico 3.3.3"],"published":"2025-01-16","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3wg7-r7q5-r2jf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-50633"},{"url":"https://github.com/cetinpy/CVE-2024-50633/issues/1"},{"url":"https://github.com/cetinpy/CVE-2024-50633"},{"url":"https://github.com/indico/indico"}],"tags":["osv","pip","exploit-available"],"epss":0.00626,"epssPercentile":0.47718,"ingestedAt":"2026-07-08T18:25:45.188Z","exploits":{"github":1,"githubRepos":["https://github.com/cetinpy/CVE-2024-50633"],"checkedAt":"2026-09-25T08:20:44.151Z"},"exploitAvailable":true,"slug":"CVE-2024-50633","body":"## Overview\n\nA Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9 allows attackers to access sensitive information via sending a crafted POST request to the component /api/principals.\n\n## Affected packages\n\n- `indico >= 3.2.9, < 3.3.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `indico 3.3.3`","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4768,"id":"CVE-2024-50633","ts":1788887205305,"field":"exploit_available","old":"false","new":"true"},{"seq":3651,"id":"CVE-2024-50633","ts":1788886321908,"field":"exploit_available","old":"true","new":"false"},{"seq":2502,"id":"CVE-2024-50633","ts":1788882989664,"field":"exploit_available","old":"false","new":"true"},{"seq":1531,"id":"CVE-2024-50633","ts":1788882403510,"field":"exploit_available","old":"true","new":"false"},{"seq":645,"id":"CVE-2024-50633","ts":1788881841071,"field":"exploit_available","old":"false","new":"true"}]}