6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ with a crafted segment value that is forwarded into build_graph_plot() and traverses foreign-key relationships (e.g. workspace__owner__password) before being projected via .values("dimension", "segment"), returning the referenced field values directly in the JSON response. This exposes sensitive data such as bcrypt password hashes, API tokens, and related users' email addresses, making it a stronger primitive than the related order_by injection where values are only leaked through ordering. This issue has been fixed in version 1.3.1.
References
-
https://github.com/makeplane/plane/security/advisories/GHSA-93x3-ghh7-72j3 x_refsource_CONFIRM
-
https://github.com/makeplane/plane/releases/tag/v1.3.1 x_refsource_MISC
Affected products
- ==< 1.3.1
Matching in nixpkgs
pkgs.xplanet
Renders an image of the earth or other planets into the X root window
pkgs.freeplane
Mind-mapping software
pkgs.headplane
Feature-complete Web UI for Headscale
pkgs.m2-planet
PLAtform NEutral Transpiler
pkgs.crossplane
NGINX configuration file parser and builder
pkgs.microplane
CLI tool to make git changes across many repos
pkgs.paper-plane
Chat over Telegram on a modern and elegant client
-
nixos-25.11 0.1.0-beta.5
- nixos-25.11-small 0.1.0-beta.5
- nixpkgs-25.11-darwin 0.1.0-beta.5
pkgs.invoiceplane
Self-hosted open source application for managing your invoices, clients and payments
pkgs.m2-mesoplanet
Macro Expander Saving Our m2-PLANET
pkgs.crossplane-cli
Utility to make using Crossplane easier
pkgs.headplane-agent
Optional sidecar process providing additional features for headplane
pkgs.biplanes-revival
Old cellphone arcade recreated for PC
pkgs.planetary_annihilation
Next-generation RTS that takes the genre to a planetary scale
pkgs.perlPackages.MathPlanePath
Points on a path through the 2-D plane
pkgs.perl5Packages.MathPlanePath
Points on a path through the 2-D plane
pkgs.dprint-plugins.g-plane-malva
CSS, SCSS, Sass and Less formatter
pkgs.python312Packages.crossplane
NGINX configuration file parser and builder
pkgs.python313Packages.crossplane
NGINX configuration file parser and builder
pkgs.python314Packages.crossplane
NGINX configuration file parser and builder
pkgs.perl538Packages.MathPlanePath
Points on a path through the 2-D plane
pkgs.perl540Packages.MathPlanePath
Points on a path through the 2-D plane
pkgs.dprint-plugins.g-plane-markup_fmt
HTML, Vue, Svelte, Astro, Angular, Jinja, Twig, Nunjucks, and Vento formatter
pkgs.dprint-plugins.g-plane-pretty_yaml
YAML formatter
pkgs.python313Packages.envoy-data-plane
Python dataclasses for the Envoy Data-Plane-API
pkgs.python314Packages.envoy-data-plane
Python dataclasses for the Envoy Data-Plane-API
pkgs.python312Packages.planetary-computer
Planetary Computer SDK for Python
-
nixos-25.11 1.0.0.post0
- nixos-25.11-small 1.0.0.post0
- nixpkgs-25.11-darwin 1.0.0.post0
pkgs.python313Packages.planetary-computer
Planetary Computer SDK for Python
-
nixos-unstable 1.0.0.post0
- nixpkgs-unstable 1.0.0.post0
- nixos-unstable-small 1.0.0.post0
-
nixos-25.11 1.0.0.post0
- nixos-25.11-small 1.0.0.post0
- nixpkgs-25.11-darwin 1.0.0.post0
pkgs.python314Packages.planetary-computer
Planetary Computer SDK for Python
-
nixos-unstable 1.0.0.post0
- nixpkgs-unstable 1.0.0.post0
- nixos-unstable-small 1.0.0.post0
pkgs.dprint-plugins.g-plane-pretty_graphql
GraphQL formatter
pkgs.haskellPackages.amazonka-iot-dataplane
Amazon IoT Data Plane SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-25.11 2.0-unstable-2025-04-16
- nixos-25.11-small 2.0-unstable-2025-04-16
- nixpkgs-25.11-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.greenplanet-energy-api
Async Python library for querying the Green Planet Energy API
pkgs.python314Packages.greenplanet-energy-api
Async Python library for querying the Green Planet Energy API
pkgs.haskellPackages.amazonka-iot-jobs-dataplane
Amazon IoT Jobs Data Plane SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-25.11 2.0-unstable-2025-04-16
- nixos-25.11-small 2.0-unstable-2025-04-16
- nixpkgs-25.11-darwin 2.0-unstable-2025-04-16
pkgs.vscode-extensions.gplane.wasm-language-tools
Language support of WebAssembly
pkgs.haskellPackages.amazonka-mediastore-dataplane
Amazon Elemental MediaStore Data Plane SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-25.11 2.0-unstable-2025-04-16
- nixos-25.11-small 2.0-unstable-2025-04-16
- nixpkgs-25.11-darwin 2.0-unstable-2025-04-16
Package maintainers
-
@KAction Dmitry Bogatov <KAction@disroot.org>
-
@selfuryon Sergei Iakovlev <siakovlev@pm.me>
-
@phanirithvij Phani Rithvij <phanirithvij2000@gmail.com>
-
@charles-dyfis-net Charles Duffy <charles@dyfis.net>
-
@Artturin Artturi N <artturin@artturin.com>
-
@alejandrosame Alejandro Sánchez Medina <alejandrosanchzmedina@gmail.com>
-
@Ericson2314 John Ericson <John.Ericson@Obsidian.Systems>
-
@siraben Siraphob Phipathananunth <bensiraphob@gmail.com>
-
@emilytrau Emily Trau <emily+nix@downunderctf.com>
-
@06kellyjac Jack <hello+nixpkgs@j-k.io>
-
@dbirks David Birks <david@birks.dev>
-
@Aleksanaa Aleksana QwQ <me@aleksana.moe>
-
@daspk04 Pratyush Das <dpratyush.k@gmail.com>
-
@svanderburg Sander van der Burg <s.vanderburg@tudelft.nl>
-
@Lassulus Lassulus <lassulus@gmail.com>
-
@igor-ramazanov Igor Ramazanov <personal@igorramazanov.tech>
-
@StealthBadger747 Erik Parawell <parawell.erik@gmail.com>
-
@onny Jonas Heinrich <onny@project-insanity.org>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>
-
@samestep Sam Estep <sam@samestep.com>