CVE-2024-47830
Plane
CVE-2024-47830 affects the Plane open-source project management tool, potentially allowing server-side request forgery (SSRF). The vulnerability stems from insecure wildcard support in /web/next.config.js
, enabling attackers to force the server to make requests to arbitrary locations. Despite a moderate CVSS score of 5.8, the SOCRadar Vulnerability Risk Score (SVRS) is 56, suggesting a potentially underestimated risk profile. This SSRF vulnerability could enable attackers to access internal resources, potentially leading to data breaches or further compromise. Organizations using Plane should upgrade to version 0.23.0 to mitigate this risk. Failing to patch this CVE can expose sensitive internal data and systems. The ability to control server-side requests makes this a significant security concern.
Description
CVE-2024-47830 is a vulnerability in Plane, an open-source project management tool. The vulnerability allows an attacker to induce the server side into performing requests to unintended locations by using the ** wildcard support to retrieve the image from any hostname. This vulnerability is fixed in version 0.23.0.
Key Insights
- The CVSS score of 9.3 indicates that this vulnerability is critical and requires immediate attention.
- The SVRS score of 38 indicates that this vulnerability is not as severe as other vulnerabilities with higher scores.
- This vulnerability is not currently being exploited in the wild.
Mitigation Strategies
- Update Plane to version 0.23.0 or later.
- Restrict access to the affected server.
- Implement a web application firewall (WAF) to block malicious requests.
Additional Information
- This vulnerability is not associated with any known threat actors or APT groups.
- CISA has not issued a warning about this vulnerability.
- If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.