Skip to content

[security][low] sentry-sdk 1.39.1 env-leak (CWE-200, CVSS 2.5) — PR #347 open #360

Description

@branben

Dependabot alert

  • Package: pip/sentry-sdk @ backend/requirements.txt
  • Installed: 1.39.1 | Vulnerable: < 1.45.1 | Fixed in: 1.45.1
  • CWE-200 Environment variables exposed to subprocesses; CVSS 2.5

Real exploitability in THIS app

Only matters if the app spawns subprocesses with inherited env containing secrets. Sound Royale passes the Sentry DSN (not a secret beyond DSN) and does not fork subprocesses with sensitive env. Risk: low.

Patch path

Dependabot PR #347 (1.39.1 -> 1.45.1) is already open. Patch release, low risk.

Action

Merge #347. Low risk.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity vulnerability or hardening

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions