QID 994766
Date Published: 2023-08-10
QID 994766: Python (Pip) Security Update for sentry (GHSA-9jcq-jf57-c62c)
An attacker with access to a token with few or no scopes can query /api/0/api-tokens/ for a list of all tokens created by a user, including tokens with greater scopes, and use those tokens in other requests.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9jcq-jf57-c62c for updates and patch information.
Vendor References
- GHSA-9jcq-jf57-c62c -
github.com/advisories/GHSA-9jcq-jf57-c62c
CVEs related to QID 994766
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9jcq-jf57-c62c | sentry |
|