Impact
Plane, a project‑management tool, had an unauthenticated field‑name injection flaw in the public issues endpoint. The entry parser accepted arbitrary values for the query parameters group_by and sub_group_by, passing them directly to the ORM without validation. Attackers could craft names that trigger unhandled FieldError or KeyError exceptions, leading to HTTP 500 responses used for denial‑of‑service. In addition, the ORM would resolve __‑separated relational paths, leaking a blind traversal oracle without revealing column data. The vulnerability does not expose sensitive information directly but allows an unauthenticated user to test for the existence of fields or relationships, giving insight into database structure.
Affected Systems
The flaw affects all installations of Plane prior to version 1.4.0 from makeplane. The fix was merged and released in the 1.4.0 tag. Deployments of earlier releases remain susceptible until an upgrade is applied.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is straightforward: an unauthenticated attacker calls the public issues endpoint with crafted group_by or sub_group_by parameters. Because the flaw triggers a 500 error or a key traversal oracle, the effort to exploit is low, especially in environments that expose the public endpoint. The risk grows if the affected instance is publicly accessible, as repeated 500 errors can exhaust server resources or reveal schema details. No privileged access or additional network traversal is required, making this a low‑bar vulnerability for adversaries who seek disruptions or information gathering.
OpenCVE Enrichment