CVE-2025-27134

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint `PATCH /api/users/:id` to set the `is_admin` field to 1. The vulnerability allows malicious low-privileged users to perform administrative actions without proper authorization. This issue has been patched in version 3.3.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:joplin_project:joplin:*:*:*:*:*:-:*:*

History

16 May 2025, 16:32

Type Values Removed Values Added
CPE cpe:2.3:a:joplin_project:joplin:*:*:*:*:*:-:*:*
CWE NVD-CWE-noinfo
References () https://github.com/laurent22/joplin/commit/12baa9827dac9da903f244c9f358e3deb264e228 - () https://github.com/laurent22/joplin/commit/12baa9827dac9da903f244c9f358e3deb264e228 - Patch
References () https://github.com/laurent22/joplin/security/advisories/GHSA-xj67-649m-3p8x - () https://github.com/laurent22/joplin/security/advisories/GHSA-xj67-649m-3p8x - Exploit, Vendor Advisory
First Time Joplin Project joplin
Joplin Project

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Joplin es una aplicación gratuita y de código abierto para tomar notas y gestionar tareas pendientes, capaz de gestionar un gran número de notas organizadas en cuadernos. Antes de la versión 3.3.3, existía una vulnerabilidad de escalada de privilegios en el servidor Joplin, que permitía a usuarios no administradores explotar el endpoint de la API `PATCH /api/users/:id` para establecer el campo `is_admin` en 1. Esta vulnerabilidad permite a usuarios malintencionados con pocos privilegios realizar acciones administrativas sin la debida autorización. Este problema se ha corregido en la versión 3.3.3.

30 Apr 2025, 16:15

Type Values Removed Values Added
References () https://github.com/laurent22/joplin/security/advisories/GHSA-xj67-649m-3p8x - () https://github.com/laurent22/joplin/security/advisories/GHSA-xj67-649m-3p8x -

30 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 15:16

Updated : 2025-05-16 16:32


NVD link : CVE-2025-27134

Mitre link : CVE-2025-27134

CVE.ORG link : CVE-2025-27134


JSON object : View

Products Affected

joplin_project

  • joplin
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo