Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54m3-95j9-v89j

Опубликовано: 17 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Sentry improperly authorizes deletion of user issue alert notifications

Impact

An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.

Patches

A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.

Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.

References

Пакеты

Наименование

sentry

pip
Затронутые версииВерсия исправления

>= 23.9.0, < 24.9.0

24.9.0

EPSS

Процентиль: 61%
0.00411
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 61%
0.00411
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-639