Executive brief
Sentry, an application monitoring platform, was found to leak sensitive integration credentials in certain error messages. When a user interacts with specific search components that fail to validate third-party responses, the system may return the integration's Client ID and Client Secret in plaintext within the HTTP response. While these credentials alone do not grant full access to data, they could be used by an attacker who has also obtained a valid API token to compromise application integrations.
Technical details
An information disclosure vulnerability exists in Sentry due to improper error handling in the 'select-requester' component. When a Search UI component with the 'async' flag enabled receives an invalid response from a third-party service, Sentry returns a 'select-requester.invalid-response' error. This error message includes a serialized version of the Sentry application, which contains the plaintext Client ID and Client Secret. The vulnerability is rooted in 'src/sentry/sentry_apps/external_requests/select_requester.py'. Attackers can observe these secrets in the underlying HTTP response, though they are not rendered in the UI. A fix is available in version 24.11.1.
Affected products
- Sentry Sentry 24.11.0
Timeline
- 2024-11-22: advisory: GHSA-v5h2-q2w4-gpcx published
- 2024-11-22: patched: Sentry version 24.11.1 released
References
- https://api.github.com/users/Christinarlong
- https://github.com/Christinarlong
- https://api.github.com/users/Christinarlong/gists%7B/gist_id%7D
- https://api.github.com/users/Christinarlong/repos
- https://avatars.githubusercontent.com/u/60594860?v=4
- https://api.github.com/users/Christinarlong/events%7B/privacy%7D