VU#762226: Plane contains multi-tenant authorization bypass vulnerability
The project management tool Plane, in versions 1.3.0 and earlier, has a vulnerability in its asset-management API. This flaw allows unauthorized users to bypass multi-tenant authorization. The API accepts workspace slugs and asset identifiers without verifying user authorization for that workspace. Consequently, an authenticated user can target assets in another workspace. They can access, delete, or duplicate files belonging to different workspaces. To exploit this, an attacker needs to authenticate and know the victim workspace's slug and asset ID. These identifiers can be found in public URLs or API data. The vulnerability could lead to sensitive file exfiltration or data destruction. Unfortunately, a patch is not yet available as Plane developers could not be reached. Users can mitigate risks by implementing network controls for the API endpoints. Enabling detailed activity logging and security alerts is also recommended. Monitoring for cross-workspace requests and unusual operations can help detect exploitation.