PT-2024-40093 · Sentry · Sentry Javascript Sdk

Published

2024-10-03

·

Updated

2024-10-03

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Sentry JavaScript SDK versions prior to 7.119.1 Sentry JavaScript SDK versions prior to 8.33.0
Description: The Sentry SDK can potentially serve as a gadget to exploit a Prototype Pollution vulnerability present in a user's application or bundled libraries. The exploitability depends on the specific details of the underlying Prototype Pollution issue. It is essential to address any Prototype Pollution vulnerabilities in the application first, as they pose a more critical security risk.
Recommendations: For Sentry JavaScript SDK versions prior to 7.119.1, update to version 7.119.1 or later. For Sentry JavaScript SDK versions prior to 8.33.0, update to version 8.33.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-593M-55HH-J8GV

Affected Products

Sentry Javascript Sdk