{"id":"CVE-2023-39349","summary":"Sentry vulnerable to privilege escalation via ApiTokensEndpoint","details":"Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with greater scopes, and use those tokens in other requests. There is no evidence that the issue was exploited on `sentry.io`. For self-hosted users, it is advised to rotate user auth tokens. A fix is available in version 23.7.2 of `sentry` and `self-hosted`. There are no known workarounds.","aliases":["GHSA-9jcq-jf57-c62c","PYSEC-2026-1912"],"modified":"2026-08-12T03:51:45.362009346Z","published":"2023-08-07T18:27:12.396Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39349.json"},"references":[{"type":"WEB","url":"https://github.com/getsentry/self-hosted/releases/tag/23.7.2"},{"type":"WEB","url":"https://github.com/getsentry/sentry/releases/tag/23.7.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39349.json"},{"type":"ADVISORY","url":"https://github.com/getsentry/sentry/security/advisories/GHSA-9jcq-jf57-c62c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39349"},{"type":"FIX","url":"https://github.com/getsentry/sentry/commit/fad12c1150d1135edf9666ea72ca11bc110c1083"},{"type":"FIX","url":"https://github.com/getsentry/sentry/pull/53850"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getsentry/self-hosted","events":[{"introduced":"25381dab2e56115a17798850b139862cc3c09ea6"},{"fixed":"c3274e82164c51a21a313ffe81d2d283da1f8ef4"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"22.1.0"},{"fixed":"23.7.2"}]}},{"type":"GIT","repo":"https://github.com/getsentry/sentry","events":[{"introduced":"9dfc86b39edec108f121d444b2fb42ce6c1f70d0"},{"fixed":"adbbcd8cfb0406be8647c6763a243e171de3d84a"},{"fixed":"fad12c1150d1135edf9666ea72ca11bc110c1083"}],"database_specific":{"cpe":"cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"22.1.0"},{"fixed":"23.7.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39349.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}