CVE-2021-23431: Cross-site Request Forgery (CSRF)
Published Aug 24, 2021
·Updated
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
Affected Software
1 affected component
Joplinapp Joplin Node.js<2.3.2
Remediation
Patch Available
Event History
Aug 24, 2021
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-23431.
2
What is the severity of CVE-2021-23431?
The severity of CVE-2021-23431 is high (8.8).
3
What is the affected software for CVE-2021-23431?
The affected software for CVE-2021-23431 is Joplin version up to exclusive 2.3.2.
4
What is the description of CVE-2021-23431?
CVE-2021-23431 is a vulnerability in Joplin that allows Cross-site Request Forgery (CSRF) attacks due to missing CSRF checks in various forms.
5
How can I fix CVE-2021-23431?
To fix CVE-2021-23431, update Joplin to version 2.3.2 or higher.