U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-53640

Change History

New CVE Received from GitHub, Inc. 7/14/2025 5:15:27 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could be misused to dump basic user details (such as name, affiliation and email) in bulk. Version 3.3.7 fixes the issue. Owners of instances that allow everyone to create a user account, who wish to truly restrict access to these user details, should consider restricting user search to managers. As a workaround, it is possible to restrict access to the affected endpoints (e.g. in the webserver config), but doing so would break certain form fields which could no longer show the details of the users listed in those fields, so upgrading instead is highly recommended.
Added CVSS V4.0

								
							
							
						
AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Added CWE

								
							
							
						
CWE-200
Added CWE

								
							
							
						
CWE-639
Added CWE

								
							
							
						
CWE-862
Added Reference

								
							
							
						
https://docs.getindico.io/en/stable/config/settings/#ALLOW_PUBLIC_USER_SEARCH
Added Reference

								
							
							
						
https://docs.getindico.io/en/stable/installation/upgrade
Added Reference

								
							
							
						
https://github.com/indico/indico/releases/tag/v3.3.7
Added Reference

								
							
							
						
https://github.com/indico/indico/security/advisories/GHSA-q28v-664f-q6wj