Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by a…
High CVSS 7.4
Summary
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML authentication, an attacker whose IdP session can assert a local user's email can pass POST /api/saml, receive a session for that local account, and access or modify the victim's notes, fi…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/laurent22/joplin/commit/b6d69d072919cbe769234f93d95ed21e1ec129b2
- https://github.com/laurent22/joplin/pull/15647
- https://github.com/laurent22/joplin/security/advisories/GHSA-5px3-4f5x-hjc5
Timeline
- nvd_ingest NVD