{"id":"GHSA-67cx-rhhq-mfhq","summary":"High severity vulnerability that affects indico","details":"## Local file disclosure through LaTeX injection\n\n### Impact\nAn external audit of the Indico codebase has discovered a vulnerability in Indico's LaTeX sanitization code, which could have malicious users to run unsafe LaTeX commands on the server. Such commands allowed for example to read local files (e.g. `indico.conf`).\n\nAs far as we know it is not possible to write files or execute code using this vulnerability.\n\n### Patches\nYou need to update to [Indico 2.2.3](https://github.com/indico/indico/releases/tag/v2.2.3) as soon as possible.\nWe also released [Indico 2.1.10](https://github.com/indico/indico/releases/tag/v2.1.10) in case you cannot update to 2.2 for some reason.\nSee https://docs.getindico.io/en/stable/installation/upgrade/ for instructions on how to update.\n\n### Workarounds\nSetting `XELATEX_PATH = None` in `indico.conf` will result in an error when building a PDF, but without being able to run xelatex, the vulnerability cannot be abused.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a thread in [our forum](https://talk.getindico.io/)\n* Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)\n\n","modified":"2024-12-02T05:43:40.309364Z","published":"2019-10-11T18:28:07Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:18:15Z","nvd_published_at":null,"cwe_ids":["CWE-77"]},"references":[{"type":"WEB","url":"https://github.com/indico/indico/security/advisories/GHSA-67cx-rhhq-mfhq"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-67cx-rhhq-mfhq"},{"type":"PACKAGE","url":"https://github.com/indico/indico"}],"affected":[{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.10"}]}],"versions":["0.98-rc1","0.98.0","0.98.1","0.98.2","0.99","1.0","1.1","1.1.1","1.1.2","1.2","1.2.1","1.2.1rc10","1.2.1rc11","1.2.1rc2","1.2.1rc4","1.2.1rc5","1.2.1rc6","1.2.1rc7","1.2.1rc9","1.2.2","1.2.2rc1","1.9.11.dev10","1.9.11.dev11","1.9.11.dev12","1.9.11.dev13","1.9.11.dev14","1.9.11.dev15","1.9.11.dev16","1.9.11.dev17","1.9.11.dev3","1.9.11.dev4","1.9.11.dev6","1.9.11.dev7","1.9.11.dev8","1.9.11.dev9","2.0","2.0.1","2.0.2","2.0.3","2.0a1","2.0rc1","2.0rc2","2.1","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json"}},{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.3"}]}],"versions":["2.2","2.2.1","2.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-67cx-rhhq-mfhq/GHSA-67cx-rhhq-mfhq.json"}}],"schema_version":"1.9.0"}