CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-47935

HIGH
8.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-05-10
Last Modified2026-05-14
Data SourcesNVD

Vulnerability Description

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.

Affected Platforms (CPE)

📦
Sentry

Sentry

= 8.2.0

References & Advisories

相關漏洞威脅