CVE-2024-45605: Improper authorization on deletion of user issue alert notifications in sentry
Impact An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
Patches A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
References - Prevent muting user alerts
Other sources
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. There are no known workarounds for this vulnerability.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the impact of CVE-2024-45605?
CVE-2024-45605 allows an authenticated user to delete alert notifications for arbitrary users, posing a potential risk to user privacy.
How can I fix CVE-2024-45605?
To fix CVE-2024-45605, ensure you implement the provided patch that properly scopes authorization checks for deletion requests.
In which versions of Sentry is CVE-2024-45605 present?
CVE-2024-45605 affects Sentry versions between 23.9.0 and 24.9.0.
Are Sentry SaaS users affected by CVE-2024-45605?
Sentry SaaS users are not impacted by CVE-2024-45605 and do not need to take any action.
How do I determine if my Sentry installation is vulnerable to CVE-2024-45605?
You can determine if your Sentry installation is vulnerable to CVE-2024-45605 by checking if you are using a version in the range from 23.9.0 to 24.9.0.