SCA: security update for sentry-sdk (GHSA-29pr-6jr8-q5jm)

medium Tenable Self-Hosted Container Security Plugin ID 408829

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the
Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is
possible to leak sensitive cookies values, including the session cookie to Sentry. These sensitive cookies
could then be used by someone with access to your Sentry issues to impersonate or escalate their
privileges within your application. In order for these sensitive values to be leaked, the Sentry SDK
configuration must have `sendDefaultPII` set to `True`; one must use a custom name for either
`SESSION_COOKIE_NAME` or `CSRF_COOKIE_NAME` in one's Django settings; and one must not be configured in
one's organization or project settings to use Sentry's data scrubbing features to account for the custom
cookie names. As of version 1.14.0, the Django integration of the `sentry-sdk` will detect the custom
cookie names based on one's Django settings and will remove the values from the payload before sending the
data to Sentry. As a workaround, use the SDK's filtering mechanism to remove the cookies from the payload
that is sent to Sentry. For error events, this can be done with the `before_send` callback method and for
performance related events (transactions) one can use the `before_send_transaction` callback method. Those
who want to handle filtering of these values on the server-side can also use Sentry's advanced data
scrubbing feature to account for the custom cookie names. Look for the `$http.cookies`, `$http.headers`,
`$request.cookies`, or `$request.headers` fields to target with a scrubbing rule. (CVE-2023-28117)

See Also

https://github.com/advisories/GHSA-29pr-6jr8-q5jm

Plugin Details

Severity: Medium

ID: 408829

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2023-28117

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/21/2023

Vulnerability Publication Date: 3/21/2023

Reference Information

CVE: CVE-2023-28117