Joplin
cpe:2.3:a:joplin_project:joplin:*:*:*:*:android:*:*, +4 more
- <= 3.5.2
A logic error has been identified in Joplin Server's delta API, affecting versions through 3.5.2. This vulnerability allows share recipients to download notes that are no longer shared with them. The issue arises because the delta API includes the latest state of items without verifying their current sharing status with the user. As a result, deleted items can be incorrectly reported as available, exposing confidential notes to users who should not have access.
Exploitation of this vulnerability allows users to access notes they should no longer have access to, potentially leading to unauthorized disclosure of confidential information.
The vulnerability can be reproduced by sharing a note with a user, then unsharing it and adding a new client to the user's account. The new client will download the note, including any recent changes, despite the user no longer having access.
Users can update to Joplin Server version 3.5.3 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.