Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42704 | Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0. |
Tue, 15 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plane
Plane plane |
|
| CPEs | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Makeplane
Makeplane plane |
Plane
Plane plane |
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Makeplane
Makeplane plane |
|
| CPEs | cpe:2.3:a:makeplane:plane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Makeplane
Makeplane plane |
|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0. | |
| Title | Plane allows server side request forgery via /_next/image endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-15T16:15:20.916Z
Reserved: 2024-10-03T14:06:12.642Z
Link: CVE-2024-47830
Updated: 2024-10-11T15:02:03.861Z
Status : Analyzed
Published: 2024-10-11T15:15:05.613
Modified: 2024-11-12T19:55:58.010
Link: CVE-2024-47830
No data.
OpenCVE Enrichment
No data.
EUVD