CVE-2023-50249: Sentry's Astro SDK vulnerable to ReDoS
Impact A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of service (DoS).
Applications that are using Sentry's Astro SDK are affected if:
1. They're using Sentry instrumentation: - they have manually registered Sentry Middleware (affected versions 7.78.0-7.86.0); - or configured Astro in SSR (server) or hybrid mode, use Astro 3.5.0 and newer and didn’t disable the automatic server instrumentation (affected versions 7.82.0-7.86.0). 2. They have configured routes with at least two path params (e.g. /foo/[p1]/bar/[p2]).
Patches The problem has been patched in @sentry/astro@7.87.0. The corresponding PR: https://github.com/getsentry/sentry-javascript/pull/9815
Workarounds We strongly recommend upgrading to the latest SDK version. However, if it's not possible, the steps to mitigate the vulnerability without upgrade are: disable auto instrumentation if you're using Astro 3.5.0 or newer and remove the manually added Sentry middleware (if it was added before).
After these changes, Sentry error reporting will still be functional, but some details such as server-side transactions (and consequently, distributed traces between client and server) will be omitted. We therefore still recommend to update to 7.87.0 as soon as you can.
References Sentry docs: Manual Setup for Astro Release notes: sentry-javascript 7.87.0 npm: @sentry/astro@7.87.0
Other sources
Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of service (DoS). This vulnerability has been patched in sentry/astro version 7.87.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50249?
CVE-2023-50249 is classified as a high severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2023-50249?
To fix CVE-2023-50249, update the @sentry/astro package to version 7.87.0 or higher.
What versions of the Sentry Astro SDK are affected by CVE-2023-50249?
CVE-2023-50249 affects Sentry's Astro SDK versions 7.78.0 to 7.86.0.
What type of vulnerability is CVE-2023-50249?
CVE-2023-50249 is a Regular Expression Denial of Service (ReDoS) vulnerability.
What are the implications of CVE-2023-50249?
The implications of CVE-2023-50249 include potential server performance degradation and service unavailability due to excessive computation times.