Sentry is vulnerable to Information Disclosure
30
Low Risk
Affected versions of this package send HTTP Authorization headers without properly redacting them, which can expose sensitive authentication information or personally identifiable information (PII). If an attacker gains access to the server or intercepts its communications, it could extract this header content and use it to hijack user sessions, escalate privileges, or exfiltrate multiple PII from the users.
You are affected if you are using a version that falls within the vulnerable range.
Sentry is vulnerable to Information Disclosure in versions 3.12.0 - 5.6.0.
Upgrade the Sentry library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant