PT-2024-40093 · Sentry · Sentry Javascript Sdk
Published
2024-10-03
·
Updated
2024-10-03
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Sentry JavaScript SDK versions prior to 7.119.1
Sentry JavaScript SDK versions prior to 8.33.0
Description:
The Sentry SDK can potentially serve as a gadget to exploit a Prototype Pollution vulnerability present in a user's application or bundled libraries. The exploitability depends on the specific details of the underlying Prototype Pollution issue. It is essential to address any Prototype Pollution vulnerabilities in the application first, as they pose a more critical security risk.
Recommendations:
For Sentry JavaScript SDK versions prior to 7.119.1, update to version 7.119.1 or later.
For Sentry JavaScript SDK versions prior to 8.33.0, update to version 8.33.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentry Javascript Sdk