Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. sentry
  4. ›
  5. CVE-2023-36829

CVE-2023-36829: Incorrect Comparison

July 6, 2023 (updated July 18, 2023)

Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the access-control-allow-credentials: true HTTP header if the Origin request header ends with the system.base-hostname option of Sentry installation. This only affects installations that have system.base-hostname option explicitly set, as it is empty by default. Impact is limited since recent versions of major browsers have cross-site cookie blocking enabled by default. However, this flaw could allow other multi-step attacks. The patch has been released in Sentry 23.6.2.

References

  • github.com/advisories/GHSA-4xqm-4p72-87h6
  • github.com/getsentry/self-hosted/releases/tag/23.6.2
  • github.com/getsentry/sentry/commit/19248fb9802c252665b802aeab02fdc65ed47dc9
  • github.com/getsentry/sentry/commit/ee44c6be35e5e464bc40637580f39867898acd8b
  • github.com/getsentry/sentry/pull/52276
  • github.com/getsentry/sentry/security/advisories/GHSA-4xqm-4p72-87h6
  • github.com/pypa/advisory-database/tree/main/vulns/sentry/PYSEC-2023-115.yaml
  • nvd.nist.gov/vuln/detail/CVE-2023-36829

Code Behaviors & Features

Detect and mitigate CVE-2023-36829 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 23.6.0 before 23.6.2

Fixed versions

  • 23.6.2

Solution

Upgrade to version 23.6.2 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-697: Incorrect Comparison

Source file

pypi/sentry/CVE-2023-36829.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:14 +0000.