Vulnerability Details CVE-2023-46729
sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. The problem has been fixed in version 7.77.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.9%
CVSS Severity
CVSS v3 Score 9.3
Products affected by CVE-2023-46729
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.26.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.27.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.28.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.28.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.29.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.30.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.31.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.31.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.32.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.32.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.33.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.34.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.35.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.36.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.37.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.37.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.37.2
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.38.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.39.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.40.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.41.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.42.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.43.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.44.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.44.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.44.2
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.45.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.46.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.47.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.48.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.49.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.50.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.51.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.51.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.51.2
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.52.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.52.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.53.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.53.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.54.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.55.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.55.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.55.2
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.56.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.57.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.58.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.58.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.59.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.59.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.59.2
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.59.3
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.60.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.60.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.61.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.61.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.62.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.63.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.64.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.65.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.66.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.67.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.68.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.69.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.70.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.71.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.72.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.73.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.74.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.74.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.75.0
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.75.1
-
cpe:2.3:a:sentry:sentry_software_development_kit:7.76.0