CyberRota Analysis
AI-GeneratedThe Joplin Server's GET /api/login_with_code/:id endpoint is vulnerable to brute-force attacks due to the lack of a login attempt limiter, allowing unauthenticated attackers to guess a nine-digit SSO authentication code without restriction. Successful exploitation grants full access to a user's notes, notebooks, and account settings, posing a significant risk to user data integrity and confidentiality. Organizations using Joplin Server versions prior to 3.7.2 should prioritize upgrading to mitigate this critical vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.