Impact
The Plane project management platform allowed users to include issue UUIDs from any workspace when accessing the modules endpoint. Because the endpoint did not verify that the specified UUID belonged to the authenticated user's workspace, a user could associate an issue that resides in a different tenant into a module in their own workspace. This cross‑tenant link is possible for any authenticated user. The weakness is categorized as a broken access control (CWE‑639).
Affected Systems
This flaw affects all installations of Plane prior to release version 1.4.0. Users running any older version of the open‑source project management tool are potentially exposed. The fix was applied in the 1.4.0 release and subsequent revisions.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑to‑moderate severity, and no EPSS data is available, implying no known public exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an authenticated user; an attacker could create or link issues across tenants to gain visibility into other tenants’ data via the linking feature. However, the impact is limited to unauthorized association of issues, and does not grant arbitrary read or write access outside module linking. Nevertheless, the cross‑tenant exposure could lead to data leakage or confusion in project organization.
OpenCVE Enrichment