CyberRota Analysis
AI-GeneratedThe vulnerability affects Plane, an open-source project management tool, which improperly trusts unverified email addresses from Gitea and self-managed GitLab OAuth deployments when email confirmation is disabled. This flaw allows an attacker to exploit the OAuth identity to log into a victim's Plane account without needing their password, posing a critical security risk. Organizations using Plane versions prior to 1.4.0 should prioritize immediate updates to mitigate this authentication bypass vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.