MEDIUM 6.5 PyPI

Sentry improperly authorizes deletion of user issue alert notifications

GHSA-54m3-95j9-v89j · CVE-2024-45605 · PYSEC-2026-1910

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.

Patches

A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.

Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes