Skip to content

Prototype Pollution gadget in JavaScript SDKs

Low
oioki published GHSA-593m-55hh-j8gv Oct 3, 2024

Package

npm @sentry/browser (npm)

Affected versions

<8.33.0

Patched versions

8.33.0

Description

Impact

In case a Prototype Pollution vulnerability is present in a user's application or bundled libraries, the Sentry SDK could potentially serve as a gadget to exploit that vulnerability. The exploitability depends on the specific details of the underlying Prototype Pollution issue.

Note

This advisory does not indicate the presence of a Prototype Pollution within the Sentry SDK itself. Users are strongly advised to first address any Prototype Pollution vulnerabilities in their application, as they pose a more critical security risk.

Patches

The issue was patched in all Sentry JavaScript SDKs starting from the 8.33.0 version.

References

Severity

Low

CVE ID

No known CVE

Weaknesses