sentry-cli is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
59
Medium Risk
The CLI loads the Sentry base URL and the authentication token independently from different configuration sources such as .sentryclirc files, environment variables, and CLI arguments. When a non-embedded auth token comes from one source and the URL from another, the token is bound to the mismatched URL instead of the value being rejected. An attacker who controls one configuration source, for example a .sentryclirc committed to a repository, can cause a token supplied elsewhere to be transmitted to an unintended server and exfiltrated. The fix binds the URL and the auth token to a single runtime source and ignores a conflicting value from another source with a warning.
You are affected if you are using a version that falls within the vulnerable range and provide the Sentry URL and a non-embedded auth token from different configuration sources.
sentry-cli is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.1.4 - 3.6.1.
Upgrade the sentry-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant