VDB
Sign up
MEDIUM5.4

GHSA-gjwp-7v3g-99pj

Cross-site Request Forgery (CSRF) in joplin

Quick fix

GHSA-gjwp-7v3g-99pj — joplin: upgrade to the fixed version with the command below.

npm install joplin@2.3.2

Details

The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joplin
Introduced in: 0Fixed in: 2.3.2
Fixnpm install joplin@2.3.2

References