CVE-2021-47935

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sentry:sentry:8.2.0:*:*:*:*:*:*:*

History

20 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Sentry 8.2.0 contiene una vulnerabilidad de ejecución remota de código que permite a superusuarios autenticados ejecutar comandos arbitrarios mediante la inyección de objetos maliciosos serializados con pickle a través del parámetro de datos de entrada del registro de auditoría. Los atacantes pueden enviar solicitudes POST manipuladas al endpoint del registro de auditoría de administrador con cargas útiles pickle comprimidas y codificadas en base64 en el campo de datos para lograr la ejecución de código con privilegios de aplicación.

14 May 2026, 17:16

Type Values Removed Values Added
First Time Sentry sentry
Sentry
CPE cpe:2.3:a:sentry:sentry:8.2.0:*:*:*:*:*:*:*
References () https://sentry.io/welcome/ - () https://sentry.io/welcome/ - Product
References () https://www.exploit-db.com/exploits/50318 - () https://www.exploit-db.com/exploits/50318 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/sentry-remote-code-execution-via-pickle-deserialization - () https://www.vulncheck.com/advisories/sentry-remote-code-execution-via-pickle-deserialization - Third Party Advisory

10 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 13:16

Updated : 2026-07-20 20:10


NVD link : CVE-2021-47935

Mitre link : CVE-2021-47935

CVE.ORG link : CVE-2021-47935


JSON object : View

Products Affected

sentry

  • sentry
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')