Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39983
HistoryMar 29, 2023 - 4:20 p.m.

Sensitive Information Disclosure

2023-03-2916:20:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
sentry-sdk
vulnerability
cookies
sensitive information
data scrubber

0.001 Low

EPSS

Percentile

38.7%

sentry-sdk is vulnerable to Sensitive Information Disclosure. The vulnerability exists in the cookies function of __init__.py when the sendDefaultPII is set to true, the SESSION_COOKIE_NAME or CSRF_COOKIE_NAME uses a custom name, and when the Sentry’s data scrubber is not configured, which allows an attacker to gain access to sensitive cookies and perform unauthorized actions.

CPENameOperatorVersion
sentry-sdkle1.13.0
sentry-sdkle1.13.0

0.001 Low

EPSS

Percentile

38.7%