PT-2025-6009 · Joplin · Joplin
Personalizedrefrigerator
·
Published
2025-02-07
·
Updated
2025-02-10
·
CVE-2024-55630
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Joplin versions prior to 3.2.8
Description
Joplin is a free, open source note taking and to-do application. The HTML sanitizer in Joplin allows the
name attribute to be specified, which can lead to a property replacement issue. If the name attribute is set to the same value as an existing document property, that property is replaced with the element. This issue can cause a denial of service, where the note viewer fails to refresh until closed and re-opened with a different note.Recommendations
For versions prior to 3.2.8, upgrade to version 3.2.8 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
name attribute in the HTML sanitizer until a patch is applied. There are no known workarounds for this vulnerability.Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joplin