Executive brief
Joplin is a note-taking application with sync and sharing capabilities. A missing protection in form submissions allowed attackers to perform unauthorized actions (such as modifying notes, changing account settings, or deleting data) by tricking users into clicking malicious links or visiting compromised websites.
Technical details
Joplin before version 2.3.2 was vulnerable to cross-site request forgery (CSRF) attacks due to missing CSRF tokens in various form handlers. An attacker could craft a malicious webpage or email that, when visited by an authenticated Joplin user, would trigger unprotected form submissions on the Joplin server. This requires user interaction (visiting the malicious page) and the victim to be logged into Joplin. The fix involved adding form tokens (CSRF tokens) to prevent these attacks, as demonstrated in commit 19b45de. The vulnerability was patched in version 2.3.2.
Affected products
- Joplin Joplin before 2.3.2
Timeline
- 2021-09-02: disclosed
- 2021-08-25: patched: Fix committed on 2021-07-24, prior to public disclosure