Site icon API Security Blog

Privilege Escalation

sentry is vulnerable to Privilege Escalation. An authenticated attacker is able to take advantage of an access token with a restricted scope by requesting a list of all user-created tokens, including those with wider scopes from the `/api/0/api-tokens/` endpoint, resulting in privilege escalation.Read More

Exit mobile version