Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. There are no known workarounds for this vulnerability.
We have discovered 15 live websites that are affected by CVE-2024-45605.
| Product | |
| Category | Error and Exception Monitoring |
| Vulnerable Domains | 15 live websites (31% of Sentry Server install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 4 versions ( 25% of all versions) |
| 3 websites | |
| 6 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites |
| .com | 3 websites |
| .it | 3 websites |
| .co | 1 websites |
| .de | 1 websites |
| .eu | 1 websites |
| .io | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.********.eu | ***,*** | ||
| ******.******.com | *,***,*** | ||
| ******.****.*.io | *,***,*** | ||
| ******.****.biz | **,***,*** | ||
| *******.*******.no | **,***,*** | ||
| *******.******************.com | **,***,*** | ||
| *********.*************.de | **,***,*** | ||
| ***.co | **,***,*** | ||
| ******.*****.no | **,***,*** | ||
| **********.************.it | **,***,*** |
FAQ