NA

CVE-2023-46729

Published: 10/11/2023 Updated: 16/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. The problem has been fixed in version 7.77.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sentry sentry software development kit

Github Repositories

A tech blog about Front-end, JavaScript and Security

About Here is a git repository for the backup and index of my blog, you can find the blog in English here: bloghulitw/en/ 從 2014 年 3 月 17 開始,在 logdown 開設了一個 Huli's Blog,內容多為技術相關文章,偶爾混雜生活記事與旅遊心得,一直經營到 2017 年 6 月,因為 logdown 逐漸沒人維護所以開始尋找新的棲