Impact
Plane’s aPITokenLogMiddleware logged user API keys in plaintext, allowing an attacker with low privileges to capture these keys and subsequently use them to perform unauthorized actions. The vulnerability is identified as CWE‑256, reflecting insecure handling of sensitive information. The primary impact is the potential theft of authentication credentials, which can be leveraged to impersonate users or gain elevated access.
Affected Systems
The affected system is the open‑source project management tool Plane by makeplane. Versions prior to 1.4.0 contain the inbound API token logging flaw; users must verify their deployment is older than v1.4.0.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity problem that can lead to significant privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting limited documented exploitation. Exploitation requires only basic attacker privileges within the application and can be achieved by accessing the logs where the plaintext tokens are stored.
OpenCVE Enrichment