CyberRota Analysis
AI-GeneratedThe vulnerability affects the Plane project management tool prior to version 1.4.0, where the PATCH endpoint for issue attachments improperly validates the issue_id in the URL, allowing unauthorized users to modify attachments belonging to other users. This flaw can lead to unauthorized ownership transfer of attachments, posing a significant risk to data integrity and user privacy. Organizations using versions prior to 1.4.0 should prioritize updating to the latest version to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0.