In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).
References
Configurations
No configuration.
History
26 Jun 2025, 18:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
24 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-24 18:15
Updated : 2025-06-26 18:58
NVD link : CVE-2025-53073
Mitre link : CVE-2025-53073
CVE.ORG link : CVE-2025-53073
JSON object : View
Products Affected
No product.
CWE
CWE-425
Direct Request ('Forced Browsing')