← Πίσω στην αναζήτηση CVE

CVE-2026-40102

Plane

Περιγραφή

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ with a crafted segment value that is forwarded into build_graph_plot() and traverses foreign-key relationships (e.g. workspace__owner__password) before being projected via .values(-dimension-, -segment-), returning the referenced field values directly in the JSON response. This exposes sensitive data such as bcrypt password hashes, API tokens, and related users- email addresses, making it a stronger primitive than the related order_by injection where values are only leaked through ordering. This issue has been fixed in version 1.3.1.

CVSS 6.5EPSS 0.295%Κίνδυνος 0.67
Προβολή πηγής
Δημοσίευση
2026-05-20 22:16:37
Επηρεαζόμενες εκδόσεις
<=1.3.0
Τύπος
Package
Τελευταία τροποποίηση
2026-07-23 15:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N