CVE-2024-45605

Improper authorization on deletion of user issue alert notifications in sentry

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. There are no known workarounds for this vulnerability.


We have discovered 15 live websites that are affected by CVE-2024-45605.

Run a Free Instant Scan




Affected Software

Product  Sentry Server
Category Error and Exception Monitoring
Vulnerable Domains15 live websites (31% of Sentry Server install base)
Vulnerable Versions
  • from 23.9 through 24.9
Vulnerable Versions Count4 versions ( 25% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Sep 17, 2024
  • Updated - Sep 18, 2024

Website Distribution by Country

Number of websites using CVE-2024-45605
United States3 websites



Germany6 websites
Italy2 websites
Russia2 websites
Switzerland1 websites
GB1 websites

Website Distribution by TLD

Number of websites using CVE-2024-45605
.com3 websites
.it3 websites
.co1 websites
.de1 websites
.eu1 websites
.io1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-45605

Top websites that are affected by CVE-2024-45605. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.********.eu Switzerland***,***
******.******.com United States*,***,***
******.****.*.io GB*,***,***
******.****.biz Russia**,***,***
*******.*******.no Germany**,***,***
*******.******************.com Germany**,***,***
*********.*************.de Germany**,***,***
***.co Germany**,***,***
******.*****.no United States**,***,***
**********.************.it Germany**,***,***
See full domain list

FAQ

CVE-2024-45605 is Authorization Bypass Through User-Controlled Key in Sentry Server
A total of 15 websites have been identified as vulnerable to CVE-2024-45605, based on global website indexing conducted by WebTechSurvey.
The Sentry Server is affected by the CVE-2024-45605 vulnerability.
Sentry Server versions up to 24.9 are vulnerable to CVE-2024-45605.
CVE-2024-45605 is resolved in version 24.9 of Sentry Server.