Denial of Service in Joplin Note Taking Application
CVE-2024-55630
5.5MEDIUM
What is CVE-2024-55630?
Joplin, a widely used open-source note-taking and to-do application, is affected by a vulnerability that stems from how its HTML sanitizer handles the name
attribute. If this attribute is assigned a value matching an existing document
property, such as querySelector
, it results in a replacement of that property with the HTML element. Consequently, users experience a denial of service as the note viewer fails to refresh properly unless closed and re-opened with a different note. All users are strongly encouraged to upgrade to version 3.2.8 to mitigate this issue, as there are no known workarounds available.
Affected Version(s)
joplin < 3.2.8