CVE-2024-47830

CRITICAL

plane < 0.23.0 - Server-Side Request Forgery via Image Hostname Wildcard

Title source: llm
STIX 2.1

Description

Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.

Scores

CVSS v3 9.3
EPSS 0.0055
EPSS Percentile 41.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
plane/plane < 0.23.0
Published Oct 11, 2024
Tracked Since Feb 18, 2026