Roundcube Webmail Hits Critical Update: New Security Fixes Target Hidden Vulnerabilities
ID: 31a91957-f6c2-59f5-928f-34002b06cb7d
STIX ID: report--31a91957-f6c2-59f5-928f-34002b06cb7d
Feed Name: securityonline.info
Roundcube Webmail 1.6.14 fixes multiple high-risk vulnerabilities — most notably a pre-auth arbitrary file write via unsafe deserialization in Redis/Memcache session handlers with potential for remote code execution — plus remote-image blocking bypasses, password-change and IMAP-injection/CSRF flaws, HTML attachment XSS, and SSRF/information disclosure; the advisory warns that Russia-linked APTs (Winter Vivern/TA473 and APT28) have targeted Roundcube (including a prior zero-day CVE-2023-5631), and recommends upgrading to 1.6.14.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
