Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-87x4-j8vh-p5qf | Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plane
Plane plane |
|
| CPEs | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plane
Plane plane |
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Makeplane
Makeplane plane |
|
| Vendors & Products |
Makeplane
Makeplane plane |
Fri, 06 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2. | |
| Title | Plane: Unauthenticated Workspace Member Information Disclosure | |
| Weaknesses | CWE-200 CWE-284 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:54:28.297Z
Reserved: 2026-03-04T17:23:59.799Z
Link: CVE-2026-30244
Updated: 2026-03-09T20:47:24.233Z
Status : Analyzed
Published: 2026-03-06T22:16:01.900
Modified: 2026-03-10T16:23:32.280
Link: CVE-2026-30244
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:06:47Z
Github GHSA