Executive brief
A vulnerability in the Sentry SDK for Next.js applications could allow attackers to trick the server into making unauthorized web requests. This component is typically used to bypass ad-blockers so that error reports can reach Sentry's monitoring service. If exploited, an attacker could potentially access internal network services, steal sensitive cloud metadata, or perform malicious actions on behalf of the server, leading to data exposure or further compromise of the infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the @sentry/nextjs SDK due to unsanitized input handling in the tunneling endpoint. When the 'tunnelRoute' option is enabled, the SDK uses Next.js rewrites to forward envelopes to Sentry. However, the 'o' (orgId) and 'p' (projectId) query parameters were not strictly validated, allowing an attacker to inject characters like slashes to manipulate the destination URL. This enables an attacker to send HTTP requests to arbitrary internal or external URLs and reflect the responses back to the user. The vulnerability can be used for internal port scanning, accessing cloud metadata services (IMDS), or facilitating XSS/CSRF attacks. The fix in version 7.77.0 introduces strict regex validation for these parameters.
Affected products
- Sentry @sentry/nextjs >= 7.26.0, < 7.77.0
Timeline
- 2023-10-30: other: Vulnerability reported to Sentry via bug bounty program
- 2023-10-31: patched: Fix merged and version 7.77.0 released
- 2023-11-01: other: Vercel implemented infrastructure-level mitigation for hosted apps
- 2023-11-09: advisory: Security advisory published
References
- https://github.com/getsentry/sentry-javascript/security/advisories/GHSA-2rmr-xw8m-22q9
- https://github.com/getsentry/sentry-javascript/pull/9415
- https://github.com/getsentry/sentry-javascript/commit/ddbda3c02c35aba8c5235e0cf07fc5bf656f81be
- https://blog.sentry.io/next-js-sdk-security-advisory-cve-2023-46729
- https://docs.sentry.io/platforms/javascript/guides/nextjs/manual-setup/
- https://github.com/getsentry/sentry-javascript