Sentry vulnerable to privilege escalation via ApiTokensEndpoint
CVE-2023-39349
What is CVE-2023-39349?
Sentry, a prominent error tracking and performance monitoring platform, has a vulnerability that allows attackers with access to limited or no-scoped tokens to query the API for a comprehensive list of all user-created tokens. This includes access to more privileged tokens, which could be utilized in subsequent API requests. This issue, which has not been reported as exploited on the Sentry cloud service, affects all versions from 22.1.0 up to 23.7.2. Users are strongly recommended to rotate their auth tokens and upgrade to version 23.7.2 or later to mitigate this security risk. No known workarounds exist for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
sentry >= 22.1.0, < 23.7.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
