Executive brief
The Sentry Python SDK, which integrates with Django web applications to monitor errors and performance, can leak sensitive session and CSRF cookies when a feature called sendDefaultPII is enabled and custom cookie names are configured. An attacker with access to Sentry issue data could use these leaked cookies to impersonate users or escalate privileges within the application.
Technical details
The vulnerability is an information disclosure issue (CWE-201, CWE-209) in the Django integration of the Sentry SDK. When sendDefaultPII is set to True and custom SESSION_COOKIE_NAME or CSRF_COOKIE_NAME values are configured in Django settings, the SDK fails to detect and redact these cookie values before transmitting them to Sentry. The vulnerability requires high privileges (administrative access to Sentry) to exploit, as an attacker must have access to Sentry issue data. The attack has no network prerequisites beyond normal SDK operation. As of version 1.14.0, the SDK automatically detects custom cookie names from Django settings and removes their values before sending data to Sentry. Affected versions are all releases prior to 1.14.0.
Affected products
- Sentry sentry-sdk <1.14.0
Timeline
- 2023-03-21: disclosed: GHSA-29pr-6jr8-q5jm published
- 2023: patched: Fixed in version 1.14.0