Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on Sentry instance. The issue has been fixed in the release 23.11.2.
References
Link | Resource |
---|---|
https://github.com/getsentry/symbolicator/commit/9db2fb9197dd200d62aacebd8efef4df7678865a | Patch Vendor Advisory |
https://github.com/getsentry/symbolicator/pull/1332 | Vendor Advisory |
https://github.com/getsentry/symbolicator/releases/tag/23.11.2 | Release Notes Vendor Advisory |
https://github.com/getsentry/symbolicator/security/advisories/GHSA-6576-pr6j-h9c6 | Mitigation Vendor Advisory |
https://github.com/getsentry/symbolicator/commit/9db2fb9197dd200d62aacebd8efef4df7678865a | Patch Vendor Advisory |
https://github.com/getsentry/symbolicator/pull/1332 | Vendor Advisory |
https://github.com/getsentry/symbolicator/releases/tag/23.11.2 | Release Notes Vendor Advisory |
https://github.com/getsentry/symbolicator/security/advisories/GHSA-6576-pr6j-h9c6 | Mitigation Vendor Advisory |
Configurations
History
21 Nov 2024, 08:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/getsentry/symbolicator/commit/9db2fb9197dd200d62aacebd8efef4df7678865a - Patch, Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/pull/1332 - Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/releases/tag/23.11.2 - Release Notes, Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/security/advisories/GHSA-6576-pr6j-h9c6 - Mitigation, Vendor Advisory |
12 Dec 2023, 14:55
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CPE | cpe:2.3:a:sentry:symbolicator:*:*:*:*:*:*:*:* | |
First Time |
Sentry symbolicator
Sentry |
|
References | () https://github.com/getsentry/symbolicator/security/advisories/GHSA-6576-pr6j-h9c6 - Mitigation, Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/commit/9db2fb9197dd200d62aacebd8efef4df7678865a - Patch, Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/pull/1332 - Vendor Advisory | |
References | () https://github.com/getsentry/symbolicator/releases/tag/23.11.2 - Release Notes, Vendor Advisory |
30 Nov 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-30 05:15
Updated : 2024-11-21 08:32
NVD link : CVE-2023-49094
Mitre link : CVE-2023-49094
CVE.ORG link : CVE-2023-49094
JSON object : View
Products Affected
sentry
- symbolicator
CWE
CWE-918
Server-Side Request Forgery (SSRF)