Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Advisory]: Prototype Pollution gadget in JavaScript SDKs #15

Open
oioki opened this issue Oct 3, 2024 · 0 comments
Open

[Security Advisory]: Prototype Pollution gadget in JavaScript SDKs #15

oioki opened this issue Oct 3, 2024 · 0 comments

Comments

@oioki
Copy link
Member

oioki commented Oct 3, 2024

Package and Versions

Package: sentry/browser
Affected Version(s): <8.33.0
Patched Version(s): 8.33.0

Description

In case a Prototype Pollution vulnerability is present in a user's application or bundled libraries, the Sentry SDK could potentially serve as a gadget to exploit that vulnerability. The exploitability depends on the specific details of the underlying Prototype Pollution issue.

Note: This advisory does not indicate the presence of a Prototype Pollution within the Sentry SDK itself. Users are strongly advised to first address any Prototype Pollution vulnerabilities in their application, as they pose a more critical security risk.

Impact

The exploitability and impact depends on the specific details of the underlying Prototype Pollution issue.

Patches

The issue was patched in all Sentry JavaScript SDKs starting from the 8.33.0 version.

Workarounds

No workaround are available.

CVSS 3.1 Score and Vector

Severity: Low

Information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant