- 漏洞ID:
- 漏洞类型:其他
- 发布日期:2024-07-18 00:00:00
- 更新时间:2024-07-19 00:00:00
- CVE编号:CVE-2024-40647
- CNNVD-ID:CNNVD-202407-1920
- 漏洞平台:SENTRY
- CVSS评分:
暂无
sentry-python是Sentry开源的一个应用程序监控软件的 Python 软件开发工具包。 sentry-python 2.8.0之前版本存在安全漏洞,该漏洞源于环境变量无意暴露在子流程中。
来源:github.com 链接:https://github.com/getsentry/sentry-python/security/advisories/GHSA-g92j-qhmh-64v2 来源:github.com 链接:https://github.com/getsentry/sentry-python/pull/3251 来源:github.com 链接:https://github.com/getsentry/sentry-python/commit/763e40aa4cb57ecced467f48f78f335c87e9bdff 来源:docs.python.org 链接:https://docs.python.org/3/library/subprocess.html 来源:docs.sentry.io 链接:https://docs.sentry.io/platforms/python/integrations/default-integrations 来源:docs.sentry.io 链接:https://docs.sentry.io/platforms/python/integrations/default-integrations/#stdlib 来源:github.com 链接:https://github.com/getsentry/sentry-python/releases/tag/2.8.0 来源:cxsecurity.com 链接:https://cxsecurity.com/cveshow/CVE-2024-40647/