Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-42704 Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Plane
Plane plane
CPEs cpe:2.3:a:makeplane:plane:*:*:*:*:*:*:*:* cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*
Vendors & Products Makeplane
Makeplane plane
Plane
Plane plane

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
CPEs cpe:2.3:a:makeplane:plane:*:*:*:*:*:*:*:*
Vendors & Products Makeplane
Makeplane plane
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.
Title Plane allows server side request forgery via /_next/image endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-15T16:15:20.916Z

Reserved: 2024-10-03T14:06:12.642Z

Link: CVE-2024-47830

cve-icon Vulnrichment

Updated: 2024-10-11T15:02:03.861Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-11T15:15:05.613

Modified: 2024-11-12T19:55:58.010

Link: CVE-2024-47830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.