Debian alert DLA-4612-1 (sentry-python)
| From: | Santiago Ruano Rincón <santiagorr@riseup.net> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4612-1] sentry-python security update | |
| Date: | Sun, 31 May 2026 23:52:13 -0300 | |
| Message-ID: | <ahzz3QOCXJVqDG3B@voleno> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4612-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Santiago Ruano Rincón May 31, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sentry-python Version : 0.13.2-1+deb11u1 CVE ID : CVE-2024-40647 Debian Bug : 1083189 A vulnerability was found in the Python SDK for Sentry.io The issue results in the unintentional exposure of environment variables to subprocesses despite the env={} setting. For Debian 11 bullseye, this problem has been fixed in version 0.13.2-1+deb11u1. We recommend that you upgrade your sentry-python packages. For the detailed security status of sentry-python please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sentry-python Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQR+lHTq7mkJOyB6t2Un3j1FEEiG7wUCahzz3QAKCRAn3j1FEEiG 7+OHAP0d926+lsLldJtEF3UHhxdboOuBzI8zAxAxwBfBFu7uHAD+OygusAaoWBGE kNkZRRjEzb/507BPMGb/+pFZ9SRZgQ8= =GrRG -----END PGP SIGNATURE-----
