CyberRota Analysis
AI-GeneratedThe vulnerability affects Joplin versions prior to 3.7.13, allowing attackers to exploit a flaw in the application authorization process. By tricking a victim into approving an attacker's identifier, the attacker can gain unauthorized access to the victim's session, enabling full read and write access to their synchronized data. Organizations using Joplin should prioritize upgrading to version 3.7.13 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic consent page, and the public packages/server/src/routes/api/application_auth.ts endpoint passes it to ApplicationModel.createAppPassword without authenticating or binding the redeemer. An attacker can cause a victim to approve the attacker's identifier, redeem a durable application ID and password, and exchange the credential for a victim session with full read and write access to synchronized data. This vulnerability is fixed in 3.7.13.