CVE-2024-24829

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 9, 2024
Updated: Feb 16, 2024
CWE ID 918

Summary

CVE-2024-24829 is a vulnerability affecting Sentry, an error tracking and performance monitoring platform. The issue lies in the Phabricator integration, which allows external services to interact with Sentry. Versions of this integration up to and including 24.1.1 contain a constrained Server Side Request Forgery (SSRF) vulnerability. An attacker can exploit this by providing unsanitized input, leading Sentry to send POST HTTP requests to arbitrary URLs, including internal IP addresses. This enables the attacker to interact with the internal network and scan local/remote ports. Sentry has released a self-hosted fix in version 24.1.2, and the issue has been mitigated on sentry.io since February 8. Users are strongly advised to upgrade as there are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share