CVE-2024-47830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
11/10/2024
Last modified:
12/11/2024

Description

Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* 0.23.0 (excluding)