Weak Authorization Control in Sentry for Unauthenticated Access to Project Issues
CVE-2025-53073

4.2MEDIUM

Key Information:

Vendor

Sentry

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-53073?

In versions 25.1.0 through 25.5.1 of Sentry, an authenticated attacker may exploit a weakness in authorization to access a project's issue endpoint. This enables the attacker to perform unauthorized actions such as adding comments without being a confirmed member of the project's team. The vulnerability arises from the reliance on a seven-digit issue ID, which is not securely handled. The issue ID can be publicly disclosed or easily predicted, leading to potential misuse.

Affected Version(s)

Sentry 25.1.0 <= 25.5.1

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.