CVE-2024-32474
- EPSS 0.43%
- Veröffentlicht 18.04.2024 20:15:17
- Zuletzt bearbeitet 15.09.2025 16:53:23
Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser...
CVE-2024-24829
- EPSS 0.47%
- Veröffentlicht 09.02.2024 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:59:48
Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such integrations, the Phabricator integration (maintained by Sentry) with version <=2...
CVE-2023-39531
- EPSS 0.31%
- Veröffentlicht 09.08.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:36
Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exch...
CVE-2023-39349
- EPSS 0.85%
- Veröffentlicht 07.08.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:15:12
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a use...
CVE-2023-36826
- EPSS 0.51%
- Veröffentlicht 25.07.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:10:40
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. T...
CVE-2022-23485
- EPSS 0.42%
- Veröffentlicht 10.12.2022 01:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:39
Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11.0 an attacker with a known valid invite link could manipulate a cookie to allow the same invite link to be reused on multiple acc...