CVE Vulnerabilities

CVE-2025-53073

Direct Request ('Forced Browsing')

Published: Jun 24, 2025 | Modified: Jun 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a projects issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the projects team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Potential Mitigations

References