We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).
Reserved 2025-06-24 | Published 2025-06-24 | Updated 2025-06-24 | Assigner mitreCWE-425 Direct Request ('Forced Browsing')
github.com/nikolas-ch/CVEs/tree/main/Sentry_Version>=25.1.0
github.com/...0/Sentry_>=25.1.0_WeakAuthorizationControl.txt
github.com/getsentry/self-hosted/releases
Support options