An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-639"
],
"nvd_published_at": "2024-09-17T20:15:05Z",
"github_reviewed_at": "2024-09-17T17:55:29Z",
"severity": "HIGH"
}