Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sentry: Inefficient Regular Expression Complexity in sentry
Vulnerability Description
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This vulnerability is fixed in 26.5.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
CWE-1333
Vulnerability Title
Sentry 资源管理错误漏洞
Vulnerability Description
getsentry sentry是getsentry公司的错误监控与日志聚合平台。 Sentry 24.4.0版本至26.5.2之前版本存在资源管理错误漏洞,该漏洞源于事件摄取管道中的正则表达式拒绝服务,可能导致攻击者控制的事件字段消耗过多的CPU时间。
CVSS Information
N/A
Vulnerability Type
N/A