GHSA-68c2-4mpx-qh95
LOWSDK versions between and including 5.16.0 and 5.19.0 allowed Sentry auth tokens to be set in the optional authToken configuration parameter, for debugging purposes. Doing so would result in the auth token being built into the application bundle, and therefore the auth token could be potentially exposed in case the application bundle is subsequently published.
- Affected
- >= 5.16.0, <= 5.19.0
- Fixed in
- 5.19.1
- Weakness
- CWE-200
- Published
- 2024-03-01
- Source
- github