CVE-2023-51451

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-51451
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-51451.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-51451
Aliases
  • GHSA-ghg9-7m82-h96r
Published
2023-12-22T21:01:21Z
Modified
2025-11-08T15:17:22.744125Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
SSRF in symbolicator via invalid protocol
Details

Symbolicator is a service used in Sentry. Starting in Symbolicator version 0.3.3 and prior to version 21.12.1, an attacker could make Symbolicator send GET HTTP requests to arbitrary URLs with internal IP addresses by using an invalid protocol. The responses of those requests could be exposed via Symbolicator's API. In affected Sentry instances, the data could be exposed through the Sentry API and user interface if the attacker has a registered account. The issue has been fixed in Symbolicator release 23.12.1, Sentry self-hosted release 23.12.1, and has already been mitigated on sentry.io on December 18, 2023. If updating is not possible, some other mitigations are available. One may disable JS processing by toggling the option Allow JavaScript Source Fetching in Organization Settings > Security & Privacy and/or disable all untrusted public repositories under Project Settings > Debug Files. Alternatively, if JavaScript and native symbolication are not required, disable Symbolicator completely in config.yml.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/getsentry/self-hosted

Affected ranges

Type
GIT
Repo
https://github.com/getsentry/self-hosted
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

20.*

20.12.1

21.*

21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0

22.*

22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0

23.*

23.1.0
23.1.1
23.10.0
23.10.1
23.11.0
23.11.1
23.11.2
23.12.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
23.7.2
23.8.0
23.9.1

Git / github.com/getsentry/symbolicator

Affected ranges

Type
GIT
Repo
https://github.com/getsentry/symbolicator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.1.0
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0

23.*

23.10.0
23.10.1
23.11.0
23.11.1
23.11.2
23.12.0
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
23.7.2
23.8.0
23.9.0
23.9.1