CVE Feed

    Dashboard / CVE / CVE-2024-32474

    CVE-2024-32474

    Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to the log data could use these leaked credentials to login to the Sentry system as superuser. Self-hosted users on affected versions should upgrade to 24.4.1 or later. Users can configure the logging level to exclude logs of the `INFO` level and only generate logs for levels at `WARNING` or more.

    Published:Apr 18, 2024
    Last Modified:Sep 15, 2025
    EPS:Apr 18, 2024
    EPSS Score:0.00733
    CVSS Score:7.3

    Affected Products

    Vendor
    Getsentry
    Product
    Sentry
    Vendor
    Sentry
    Product
    Sentry

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High