Insecure Permissions in Roundcube Email Clients by Roundcube
CVE-2018-1000071

7.5HIGH

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
13 March 2018

What is CVE-2018-1000071?

The enigma plugin in Roundcube Webmail versions 1.3.4 and earlier exposes a security flaw due to insecure permissions. This vulnerability allows malicious actors to potentially exfiltrate GPG private keys over network connectivity, posing a significant risk to user data confidentiality. It is imperative for users and administrators to be aware of this issue and take the necessary precautions to mitigate the associated risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.