CVE-2023-50249
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of service (DoS). This vulnerability has been patched in sentry/astro version 7.87.0.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0017
Percentile
0,4th
Updated
EPSS Score Trend (Last 90 Days)
400
Uncontrolled Resource Consumption
DraftCommon Consequences
Security Scopes Affected:
Availability
Access Control
Other
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Bypass Protection Mechanism
Other
Applicable Platforms
All platforms may be affected
1333
Inefficient Regular Expression Complexity
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
Application
Astro by Sentry
Version Range Affected
From
7.78.0
(inclusive)
To
7.87.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:sentry:astro:*:*:*:*:*:node.js:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/getsentry/sentry-javascript/commit/fe24eb5eefa9d27b14b2b6f9e…
https://github.com/getsentry/sentry-javascript/pull/9815
https://github.com/getsentry/sentry-javascript/security/advisories/GHSA-x3v3-8x…
https://github.com/getsentry/sentry-javascript/commit/fe24eb5eefa9d27b14b2b6f9e…
https://github.com/getsentry/sentry-javascript/pull/9815
https://github.com/getsentry/sentry-javascript/security/advisories/GHSA-x3v3-8x…