Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a critical vulnerability in the open-source project management tool Plane. The issue allows authenticated users to create webhooks that redirect to internal network addresses, potentially exposing sensitive cloud metadata and other internal resources. While a fix is available, confirming exposure is the primary concern.
- Redirects expose internal data.
- Critical risk to internal resources.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can trick the Plane application into fetching sensitive internal resources by chaining a redirect vulnerability in its webhook feature. A user with the ability to create workspaces can register a webhook that points to an external server controlled by the attacker. This server then responds with a redirect to an internal network address. Plane's worker, following this redirect without proper validation, fetches data from the internal address, such as cloud metadata, and stores it where the attacker can access it.
- Requires ability to create a workspace.
- Triggered by a malicious webhook redirect.
- Leads to internal data exposure.
Live Threat
Current exploitation, exposure, and threat context
A user with the ability to create a workspace could configure a webhook to redirect to an internal network resource. The Plane worker may then fetch sensitive information from these internal resources, such as cloud metadata, and store it where an attacker could retrieve it via the webhook logs API.
- Internal network resources.
- Webhook redirects to internal addresses.
- Sensitive data exposure to attackers.
Operational Fix
Recommended remediation, mitigation, and detection steps
The project management tool's webhook functionality can be exploited by an attacker to access internal resources, including cloud metadata, by redirecting requests to internal addresses. Infrastructure or platform teams responsible for the Plane deployment should first identify all instances of the affected technology, determine their business criticality and network exposure, and then confirm the accountable owner. Planning for remediation should follow, prioritizing the most exposed and critical systems.
- Platform or infrastructure teams own this.
- Verify webhook configurations and network exposure.
- Plan updates during scheduled maintenance.