CVE-2024-45605Medium· 6.5▾ SunlitSentry improperly authorizes deletion of user issue alert notifications
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
sentry >= 23.9.0, < 24.9.0Upgrade to a patched release:
sentry 24.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)