Security updates 1.4.4, 1.3.11 and 1.2.10 released
29 April 2020
We just published service and security updates to the stable version 1.4 and the LTS versions 1.3 and 1.2 of Roundcube Webmail. They contain four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker.
- CSRF attack can cause an authenticated user to be logged out
- Cross-Site Scripting (XSS) via malicious HTML content (
- Remote code execution via crafted config options (
- Path traversal vulnerability allowing local file inclusion via crafted ‘plugins’ option (
The latter two vulnerabilities are classified minor because they only affect Roundcube installations with public access to the Roundcube installer. That’s generally a high-risk situation and is expected to be rare or practically non-existent in productive Roundcube deployments. However, the fixes are done in core in order to also prevent from future and yet unknown attack vectors.
We strongly recommend to update all productive installations of Roundcube with this new versions.
** Credits to the security researchers: Matei “Mal” BadanoiuReturn to News overview