PT-2024-24600 · Sentry · Sentry

Lluuaapp

·

Published

2024-04-18

·

Updated

2025-09-15

·

CVE-2024-32474

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sentry versions prior to 24.4.1
Description Sentry is an error tracking and performance monitoring platform. When authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the event : auth-index.validate superuser. An attacker with access to the log data could use these leaked credentials to login to the Sentry system as superuser.
Recommendations For Sentry versions prior to 24.4.1, upgrade to 24.4.1 or later. As a temporary workaround, consider configuring the logging level to exclude logs of the INFO level and only generate logs for levels at WARNING or higher.

Exploit

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-32474
GHSA-6CJM-4PXW-7XP9

Affected Products

Sentry