PT-2026-86398 · Plane · Plane
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.3
Description
Authenticated attackers can post comments to arbitrary issues across different workspaces. This occurs because the software fails to validate whether issues belong to the deploy board's project when using the public comment endpoint. The attack is executed by supplying a specific
issue id parameter to the public deploy-board comment endpoint.Recommendations
Update to version 1.4.3 or later.
Restrict access to the public deploy-board comment endpoint to minimize the risk of unauthorized comment posting.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane