---
cve: "CVE-2024-55630"
severity: "LOW"
cvss: 3.3
epss: "0.3%"
vendor: "laurent22"
kev: false
exploited: false
published: "2025-02-07 23:15:13"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-24T20:14:12+02:00"
---

# CVE-2024-55630

> 3.3 LOW · 🧪 PoC

## Beschreibung

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that property is replaced with the element. This vulnerability's only known impact is denial of service. The note viewer fails to refresh until closed and re-opened with a different note. This issue has been addressed in version 3.2.8 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- d45864888a6ffa5ed8883ebeb15bdc0a7c564a3d (Commit)
- e70efcbd60ce62f06e77c183b362c74e636c02d9 (Commit)

## Referenzen

- <https://github.com/laurent22/joplin/security/advisories/GHSA-5cch-jr52-qffh>
- <https://github.com/laurent22/joplin/commit/e70efcbd60ce62f06e77c183b362c74e636c02d9>
- <https://en.wikipedia.org/wiki/DOM_clobbering>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-55630) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
