SCA: security update for sentry (GHSA-7pq6-v88g-wf3w)

critical Tenable Self-Hosted Container Security Plugin ID 412180

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was
discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty
program. The vulnerability allows an attacker to take over any user account by using a malicious SAML
Identity Provider and another organization on the same Sentry instance. The victim email address must be
known in order to exploit this vulnerability. The Sentry SaaS fix was deployed on Jan 14, 2025. For self
hosted users; if only a single organization is allowed `(SENTRY_SINGLE_ORGANIZATION = True)`, then no
action is needed. Otherwise, users should upgrade to version 25.1.0 or higher. There are no known
workarounds for this vulnerability. (CVE-2025-22146)

See Also

https://github.com/advisories/GHSA-7pq6-v88g-wf3w

Plugin Details

Severity: Critical

ID: 412180

Version: Revision 1.16

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.59

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2025-22146

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/15/2025

Vulnerability Publication Date: 1/15/2025

Reference Information

CVE: CVE-2025-22146

cwe: CWE-287