PT-2024-24092 · Plane · Plane
Sylwia-Budzynska
·
Published
2024-04-10
·
Updated
2024-04-24
·
CVE-2024-31461
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 0.17-dev
Description
The issue is a Server-Side Request Forgery (SSRF) vulnerability that may allow an attacker to send arbitrary requests from the server hosting the application, potentially leading to unauthorized access to internal systems. The impact includes unauthorized access to internal services, potential leakage of sensitive information, and manipulation of internal systems by interacting with internal APIs.
Recommendations
For versions prior to 0.17-dev, update to version 0.17-dev to resolve the issue.
As a temporary workaround, consider restricting outgoing network connections from servers hosting the application to essential services only.
Additionally, implement strict input validation on URLs or parameters that are used to generate server-side requests.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane