Sentry's Astro SDK vulnerable to ReDoS
CVE-2023-50249
7.5HIGH
What is CVE-2023-50249?
A Regular Expression Denial of Service (ReDoS) vulnerability has been discovered in the Astro SDK versions 7.78.0 to 7.86.0 of Sentry's JavaScript SDK. This flaw allows an attacker to exploit specific conditions to induce excessive computational processes on the server, resulting in denial of service. Affected users are advised to upgrade to version 7.87.0, which includes the necessary patches to address this issue.
Affected Version(s)
sentry-javascript >= 7.78.0, < 7.87.0
