Denial of Service in Joplin Note Taking Application
CVE-2024-55630

5.5MEDIUM

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
7 February 2025

What is CVE-2024-55630?

Joplin, a widely used open-source note-taking and to-do application, is affected by a vulnerability that stems from how its HTML sanitizer handles the name attribute. If this attribute is assigned a value matching an existing document property, such as querySelector, it results in a replacement of that property with the HTML element. Consequently, users experience a denial of service as the note viewer fails to refresh properly unless closed and re-opened with a different note. All users are strongly encouraged to upgrade to version 3.2.8 to mitigate this issue, as there are no known workarounds available.

Affected Version(s)

joplin < 3.2.8

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-55630 : Denial of Service in Joplin Note Taking Application