CVE-2023-49094
CVSS V2 None
CVSS V3 None
Description
Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on Sentry instance. The issue has been fixed in the release 23.11.2.
Overview
- CVE ID
- CVE-2023-49094
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-30T04:49:37.404Z
- Last Modified Date
- 2023-11-30T04:49:37.404Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/getsentry/symbolicator/security/advisories/GHSA-6576-pr6j-h9c6 | x_refsource_CONFIRM |
https://github.com/getsentry/symbolicator/pull/1332 | x_refsource_MISC |
https://github.com/getsentry/symbolicator/commit/9db2fb9197dd200d62aacebd8efef4df7678865a | x_refsource_MISC |
https://github.com/getsentry/symbolicator/releases/tag/23.11.2 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-49094 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49094 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 13:10:39 | Added to TrackCVE |