GHSA-m4hc-m2v6-hfw8

Suggest an improvement
Source
https://github.com/advisories/GHSA-m4hc-m2v6-hfw8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-m4hc-m2v6-hfw8/GHSA-m4hc-m2v6-hfw8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-m4hc-m2v6-hfw8
Aliases
Published
2023-07-25T17:19:48Z
Modified
2024-10-26T23:00:50.631363Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Improper authorization on debug and artifact file downloads
Details

Impact

An authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project.

Patches

A patch was issued to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them.

Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher.

References

Database specific
{
    "nvd_published_at": "2023-07-25T19:15:11Z",
    "cwe_ids": [
        "CWE-285"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-25T17:19:48Z"
}
References

Affected packages

PyPI / sentry

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.21.0
Fixed
23.5.2

Affected versions

8.*

8.21.0
8.22.0

9.*

9.0.0rc1
9.0.0
9.1.0
9.1.1
9.1.2

10.*

10.0.0
10.0.1

20.*

20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1

21.*

21.1.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
21.10.0
21.11.0
21.12.0

22.*

22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
22.10.0
22.11.0
22.12.0

23.*

23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1