PT-2022-16019 · Sentry · Sentry
Mdtrop
·
Published
2022-12-10
·
Updated
2022-12-13
·
CVE-2022-23485
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sentry versions prior to 22.11.0
Description
Sentry is an error tracking and performance monitoring platform. An attacker with a known valid invite link could manipulate a cookie to allow the same invite link to be reused on multiple accounts when joining an organization. As a result, an attacker with a valid invite link can create multiple users and join an organization they may not have been originally invited to.
Recommendations
For versions prior to 22.11.0, update to version 22.11.0 or later to resolve the issue.
For self-hosted Sentry installs that cannot upgrade, disable the invite functionality by editing the
sentry.conf.py file and setting SENTRY FEATURES["organizations:invite-members"] to False, then restart the Sentry web service.Exploit
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sentry