Headline
GHSA-54m3-95j9-v89j: Sentry improperly authorizes deletion of user issue alert notifications
Impact
An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
Patches
A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
References
Package
pip sentry (pip)
Affected versions
>= 23.9.0, < 24.9.0
Patched versions
24.9.0
Description
Impact
An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
Patches
A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
References
- Prevent muting user alerts
References
- GHSA-54m3-95j9-v89j
- getsentry/sentry#77093
- getsentry/sentry@5902582
geoffg-sentry published to getsentry/sentry
Sep 17, 2024
Published to the GitHub Advisory Database
Sep 17, 2024
Reviewed
Sep 17, 2024
Last updated
Sep 17, 2024