CVE-2024-47830: Plane allows server side request forgery via /_next/image endpoint
Plane is an open-source project management tool. Plane uses the wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47830?
CVE-2024-47830 is classified as a moderate severity vulnerability due to the potential for server-side request forgery.
How do I fix CVE-2024-47830?
To resolve CVE-2024-47830, update your Plane installation to a version greater than 0.23.0, which includes the necessary security patches.
What software is affected by CVE-2024-47830?
CVE-2024-47830 affects the Plane project management tool up to version 0.23.0.
What type of vulnerability is CVE-2024-47830?
CVE-2024-47830 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2024-47830 be exploited remotely?
Yes, CVE-2024-47830 can be exploited remotely, allowing an attacker to make unauthorized requests from the server.