#VU100911 Information disclosure in sentry - CVE-2024-53253
Published: November 25, 2024
sentry
Sentry
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a specific error message generated by the Sentry platform can include a
plaintext Client ID and Client Secret for an application integration. A remote attacker can send a specially crafted request and obtain the integration Client Secret.