Vulnerabilidades en getsentry
25 resultadosAnálisis Vexday
Getsentry possui 25 vulnerabilidades registradas, com 4 classificadas como críticas, porém nenhuma sob ataque ativo conhecido. A fraqueza dominante é CWE-287 (autenticação imprópria), indicando problemas recorrentes no controle de acesso. O ritmo de descoberta é moderado, com apenas 2 CVEs nos últimos 90 dias, sugerindo risco estável, embora a presença de críticas justifique monitoramento contínuo das patches.
CVE-2023-39349HIGHSentry vulnerable to privilege escalation via ApiTokensEndpointEPSS 1.1%CVE-2023-50249HIGHSentry's Astro SDK vulnerable to ReDoSEPSS 0.8%CVE-2023-49094MEDIUMSymbolicator Server Side Request Forgery vulnerabilityEPSS 0.7%CVE-2025-53099MEDIUMSentry Missing Invalidation of Authorization Codes During OAuth Exchange and RevocationEPSS 0.7%CVE-2023-36829MEDIUMSentry CORS misconfiguration vulnerabilityEPSS 0.7%CVE-2023-28117HIGHSentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`EPSS 0.6%CVE-2023-36826HIGHSentry vulnerable to improper authorization on debug and artifact file downloadsEPSS 0.6%CVE-2024-53253MEDIUMSentry's improper error handling leaks Application Integration Client SecretEPSS 0.6%CVE-2023-46729CRITICALSentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpointEPSS 0.6%CVE-2026-42354CRITICALSentry: Improper authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2025-22146CRITICALImproper authentication on SAML SSO process allows user impersonation in sentryEPSS 0.6%CVE-2024-35196LOWSlack integration leaks sensitive information in logs in SentryEPSS 0.6%CVE-2023-51451MEDIUMSSRF in symbolicator via invalid protocolEPSS 0.5%CVE-2024-24829MEDIUMSSRF in Sentry via Phabricator integrationEPSS 0.5%CVE-2024-41656HIGHSentry vulnerable to stored Cross-Site Scripting (XSS)EPSS 0.5%CVE-2026-27197CRITICALSentry: Improper Authentication on SAML SSO process allows user identity linkingEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2022-23485MEDIUMInvite code reuse via cookie manipulation in sentryEPSS 0.4%CVE-2024-45605MEDIUMImproper authorization on deletion of user issue alert notifications in sentryEPSS 0.4%CVE-2024-45606HIGHImproper authorization on muting of alert rules in sentryEPSS 0.4%