CVE-2025-53073: Medium severity Sentry sentry vulnerability
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53073?
CVE-2025-53073 is classified as a high severity vulnerability due to its potential for unauthorized access and actions on a project's issue endpoint.
How do I fix CVE-2025-53073?
To fix CVE-2025-53073, update Sentry to version 25.5.2 or later, which addresses this authorization flaw.
Which versions of Sentry are affected by CVE-2025-53073?
CVE-2025-53073 affects Sentry versions from 25.1.0 through 25.5.1.
What type of attack is associated with CVE-2025-53073?
CVE-2025-53073 allows an authenticated attacker to conduct unauthorized actions, such as adding comments to issues they are not a member of.
Can CVE-2025-53073 be exploited without knowledge of the project team?
Yes, an attacker can exploit CVE-2025-53073 without being a member of the project's team, as long as they know the seven-digit issue ID.