Weak Authorization Control in Sentry for Unauthenticated Access to Project Issues
CVE-2025-53073
4.2MEDIUM
What is CVE-2025-53073?
In versions 25.1.0 through 25.5.1 of Sentry, an authenticated attacker may exploit a weakness in authorization to access a project's issue endpoint. This enables the attacker to perform unauthorized actions such as adding comments without being a confirmed member of the project's team. The vulnerability arises from the reliance on a seven-digit issue ID, which is not securely handled. The issue ID can be publicly disclosed or easily predicted, leading to potential misuse.
Affected Version(s)
Sentry 25.1.0 <= 25.5.1
