#VU126921 Authorization bypass through user-controlled key in sentry - CVE-2024-45605
Published: September 17, 2024 / Updated: April 23, 2026
sentry
Sentry
Description
The vulnerability allows a remote user to delete user issue alert notifications for arbitrary users.
The vulnerability exists due to authorization bypass through a user-controlled key in the user issue alert notification deletion endpoint when handling deletion requests with a known alert ID. A remote user can send a crafted deletion request to delete user issue alert notifications for arbitrary users.