PT-2026-1101 · Plane · Plane

CVE-2025-69284

·

Publicado

2026-01-02

·

Atualizado

2026-01-02

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.2.0
Description Plane is an open-source project management tool. A guest user, lacking the necessary permissions, could access the /api/workspaces/:slug/members/ endpoint and list users within a workspace they have joined. The display name in the response corresponds to the user's email address, potentially allowing a malicious guest to identify the email addresses of administrator users. The API endpoint /api/workspaces/:slug/members/ is vulnerable. The variable display name contains the email handler.
Recommendations Update to version 1.2.0 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69284
GHSA-7QX6-6739-C7QR

Produtos afetados

Plane