github getsentry/self-hosted 23.11.2

latest releases: 24.9.0, 24.8.0, 24.7.1...
9 months ago

Security Patch Fix

  • We have fixed a security vulnerability with symbolicator related to the forked reqwest library
    • An attacker could make symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint
    • The response could be reflected to the attacker if they have an account on Sentry instance.
  • Our fix now runs the IP filter on every request in a redirect chain

Don't miss a new self-hosted release

NewReleases is sending notifications on new releases.