Impact
The Sentry exporter in OpenTelemetry Collector Contrib processes the OTLP sender‑controlled service.name resource attribute. Before validating, the exporter extracts the project slug and passes the raw slug to the client layer, where it is interpolated into a Sentry API URL. Because the exporter does not apply its runtime validation regex, special characters in the slug can transform the expected path suffix into query data or introduce slash and dot segments that traverse directories when the Sentry deployment normalises them. The Collector then uses its operator‑configured bearer token to issue the request. A malformed service.name lets an attacker direct the exporter to authentication‑protected administrative, organization, member, or key endpoints inside the configured Sentry organisation, redirecting subsequently exported telemetry.
Affected Systems
All OpenTelemetry Collector Contrib releases prior to v0.154.0 that include the Sentry exporter are vulnerable. The issue is fixed starting with release v0.154.0, which adds runtime validation of the project slug derived from service.name. The affected repository is open‑telemetry/opentelemetry‑collector‑contrib, specifically the exporter module at exporter/sentryexporter.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability poses a moderate risk. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV, indicating no public exploitation reports yet. Exploitation requires an attacker to inject telemetry into a collector that has the Sentry exporter enabled; once that occurs, the operator bearer token can be leveraged to access privileged API endpoints, including administrative and organization configuration endpoints. The potential impact includes full access to all data and administrative functions within the Sentry organization, although cross‑organization reach is limited by Sentry’s own token middleware.
OpenCVE Enrichment
Github GHSA