QID 994797

Date Published: 2023-08-10

QID 994797: Python (Pip) Security Update for sentry (GHSA-hgj4-h2x3-rfx4)

An attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-hgj4-h2x3-rfx4 for updates and patch information.
    Vendor References

    CVEs related to QID 994797

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hgj4-h2x3-rfx4 sentry URL Logo github.com/advisories/GHSA-hgj4-h2x3-rfx4