getsentry sentry
cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*
- >= 21.12.0, < 26.2.0
A critical vulnerability has been identified in Sentry's SAML Single Sign-On (SSO) implementation, affecting versions 21.12.0 prior to 26.2.0. This vulnerability allows an attacker to take over any user account by exploiting a malicious SAML Identity Provider and targeting another organization on the same Sentry instance. Self-hosted users are at risk only if more than one organization is configured and the malicious user has permissions to modify SSO settings for another organization.
Exploitation of this vulnerability allows for unauthorized takeover of user accounts via the SAML SSO process.
Users can upgrade to Sentry version 26.2.0 or higher. For self-hosted Sentry users with only a single organization allowed, no action is needed. Additionally, enabling user account-based two-factor authentication can help prevent account takeover.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.