Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-24829— SSRF in Sentry via Phabricator integration

Quick assessment

Affected
getsentry sentry
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mobileiron Sentry是美国思可信(Mobileiron)公司的一款智能网关产品。 Mobileiron Sentry 9.1.0至24.1.2之前版本存在代码问题漏洞,该漏洞源于Phabricator存在服务器请求伪造漏洞。

CVSS 4.3 · Medium EPSS 0.47% · P39
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-24829

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SSRF in Sentry via Phabricator integration
Source: CVE Program / CVE List V5
Vulnerability Description
Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such integrations, the Phabricator integration (maintained by Sentry) with version <=24.1.1 contains a constrained SSRF vulnerability. An attacker could make Sentry send POST HTTP requests to arbitrary URLs (including internal IP addresses) by providing an unsanitized input to the Phabricator integration. However, the body payload is constrained to a specific format. If an attacker has access to a Sentry instance, this allows them to: 1. interact with internal network; 2. scan local/remote ports. This issue has been fixed in Sentry self-hosted release 24.1.2, and has already been mitigated on sentry.io on February 8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
Mobileiron Sentry 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mobileiron Sentry是美国思可信(Mobileiron)公司的一款智能网关产品。 Mobileiron Sentry 9.1.0至24.1.2之前版本存在代码问题漏洞,该漏洞源于Phabricator存在服务器请求伪造漏洞。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
getsentry sentry >= 9.1.0, < 24.1.2 -

II. Public POCs for CVE-2024-24829

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-24829

登录查看更多情报信息。

Patches & Fixes for CVE-2024-24829 (1)

Vendor Advisories for CVE-2024-24829 (1)

Other References for CVE-2024-24829 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-24829

No comments yet


Leave a comment