-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from commit #66393 which added logging of the 'validator' parameter in auth_index.py. The security fix in commit d5b3456 explicitly removed the 'validator' field from logging extras. Since the vulnerability description specifically references the 'auth-index.validate_superuser' log event and CWE-117/312, this function's logging behavior matches the described credential leakage mechanism. The direct correlation between the vulnerability report and the patched code change provides high confidence in this assessment.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| sentry | pip | >= 24.3.0, < 24.4.1 | 24.4.1 |
Ongoing coverage of React2Shell