Junglewise Threat Intelligence

CVE-2024-53253: Sentry information disclosure in Search UI component error handling

CVE-2024-53253 · Severity: medium · CVSS 5.3 · Published 2024-11-22

Technologies: sentry (PyPI), Sentry. Vendors: PyPI, Sentry.

Executive brief

Sentry, an application monitoring platform, was found to leak sensitive integration credentials in certain error messages. When a user interacts with specific search components that fail to validate third-party responses, the system may return the integration's Client ID and Client Secret in plaintext within the HTTP response. While these credentials alone do not grant full access to data, they could be used by an attacker who has also obtained a valid API token to compromise application integrations.

Technical details

An information disclosure vulnerability exists in Sentry due to improper error handling in the 'select-requester' component. When a Search UI component with the 'async' flag enabled receives an invalid response from a third-party service, Sentry returns a 'select-requester.invalid-response' error. This error message includes a serialized version of the Sentry application, which contains the plaintext Client ID and Client Secret. The vulnerability is rooted in 'src/sentry/sentry_apps/external_requests/select_requester.py'. Attackers can observe these secrets in the underlying HTTP response, though they are not rendered in the UI. A fix is available in version 24.11.1.

Affected products

  • Sentry Sentry 24.11.0

Timeline

  • 2024-11-22: advisory: GHSA-v5h2-q2w4-gpcx published
  • 2024-11-22: patched: Sentry version 24.11.1 released

References

Related threats