Executive Summary

Informations
Name CVE-2024-40647 First vendor Publication 2024-07-18
Vendor Cve Last vendor Modification 2024-07-19

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses despite the `env={}` setting. In Python's `subprocess` calls, all environment variables are passed to subprocesses by default. However, if you specifically do not want them to be passed to subprocesses, you may use `env` argument in `subprocess` calls. Due to the bug in Sentry SDK, with the Stdlib integration enabled (which is enabled by default), this expectation is not fulfilled, and all environment variables are being passed to subprocesses instead. The issue has been patched in pull request #3251 and is included in sentry-sdk==2.8.0. We strongly recommend upgrading to the latest SDK version. However, if it's not possible, and if passing environment variables to child processes poses a security risk for you, you can disable all default integrations.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40647

Sources (Detail)

https://docs.python.org/3/library/subprocess.html
https://docs.sentry.io/platforms/python/integrations/default-integrations
https://docs.sentry.io/platforms/python/integrations/default-integrations/#st...
https://github.com/getsentry/sentry-python/commit/763e40aa4cb57ecced467f48f78...
https://github.com/getsentry/sentry-python/pull/3251
https://github.com/getsentry/sentry-python/releases/tag/2.8.0
https://github.com/getsentry/sentry-python/security/advisories/GHSA-g92j-qhmh...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2024-07-19 17:27:23
  • Multiple Updates
2024-07-18 21:27:24
  • First insertion