sentry-cli is vulnerable to Exposure of Sensitive Information
55
Medium Risk
When sentry-cli build snapshots uploads images to Objectstore, affected native binaries attach the Sentry bearer token in the HTTP Authorization header in addition to the Objectstore-specific credential. That sends a long-lived Sentry secret to the Objectstore service boundary where it is no longer required. The patch removes the Sentry token from Objectstore requests and relies on Objectstore authentication only.
You are affected if you are using a version that falls within the vulnerable range.
sentry-cli is vulnerable to Exposure of Sensitive Information in versions 3.4.0 - 3.4.1.
Upgrade the sentry-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant