SB2024060316 - Inclusion of Sensitive Information in Log Files in Sentry
Published: June 3, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2024-35196)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files within Slack integration. A remote attacker can read the log files and gain access to sensitive data.
Remediation
Install update from vendor's website.
References
- https://github.com/getsentry/sentry/security/advisories/GHSA-c2g2-gx4j-rj3j
- https://github.com/getsentry/sentry/pull/70508
- https://api.slack.com/authentication/verifying-requests-from-slack#app-management-updates
- https://api.slack.com/authentication/verifying-requests-from-slack#deprecation
- https://api.slack.com/authentication/verifying-requests-from-slack#regenerating
- https://develop.sentry.dev/integrations/slack
- https://github.com/getsentry/sentry/blob/17d2b87e39ccd57e11da4deed62971ff306253d1/src/sentry/conf/server.py#L1307