Impact
A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.
Patches
You should to update to Indico 3.3.8 as soon as possible.
See the docs for instructions on how to update.
Workarounds
It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.
For more information
If you have any questions or comments about this advisory:
Impact
A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.
Patches
You should to update to Indico 3.3.8 as soon as possible.
See the docs for instructions on how to update.
Workarounds
It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.
For more information
If you have any questions or comments about this advisory: