An authenticated user may delete user issue alert notifications for arbitrary users given a known alert ID.
A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications.
Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher.
{ "nvd_published_at": "2024-09-17T20:15:05Z", "cwe_ids": [ "CWE-639" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-09-17T17:55:29Z" }