<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:19:41.540467+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-32474</id>
    <title>CVE-2024-32474 — Sentry's superuser cleartext password leaked in logs</title>
    <updated>2026-10-03T06:19:41.578067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> getsentry sentry</p>
<p>Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to the log data could use these leaked credentials to login to the Sentry system as superuser. Self-hosted users on affected versions should upgrade to 24.4.1 or later. Users can configure the logging level to exclude logs of the `INFO` level and only generate logs for levels at `WARNING` or more.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-32474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6cjm-4pxw-7xp9</id>
    <title>GHSA-6cjm-4pxw-7xp9 — Sentry vulnerable to leaking superuser cleartext password in logs</title>
    <updated>2026-10-03T06:19:41.578136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: sentry</p>
<p>### Impact
When authenticating as a superuser to a self-hosted Sentry instance with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to the log data could use these leaked credentials to login to the Sentry system as superuser.</p>
<p>### Patches
- Self-hosted users on affected versions should upgrade to 24.4.1 or later.
- Sentry SaaS users do not need to take any action. This vulnerability is not applicable to SaaS.</p>
<p>### Workarounds
Users can configure the logging level to exclude logs of the `INFO` level and only generate logs for levels at `WARNING` or higher. For details on configuring self-hosted Sentry's logging level see our documentation at: https://develop.sentry.dev/config/#logging</p>
<p>### References
- Bug introduced in https://github.com/getsentry/sentry/pull/66393
- Security fix in https://github.com/getsentry/sentry/pull/69148</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6cjm-4pxw-7xp9"/>
  </entry>
</feed>
