sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
64
Medium Risk
In vulnerable versions, credentials—including tokens, environment/rc-provided hosts, and custom headers—could be sent to untrusted or attacker-controlled destinations, exposing them to credential exfiltration or phishing attacks. The vulnerability was due to missing checks that allowed Sentry tokens and custom headers to be included with requests to arbitrary URLs, rather than ensuring they were only sent to trusted Sentry hosts.
You are affected if you are using a version that falls within the vulnerable range.
sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.2.0 - 0.29.1.
Upgrade the sentry library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant