Insecure Permissions in Roundcube Email Clients by Roundcube
CVE-2018-1000071
7.5HIGH
What is CVE-2018-1000071?
The enigma plugin in Roundcube Webmail versions 1.3.4 and earlier exposes a security flaw due to insecure permissions. This vulnerability allows malicious actors to potentially exfiltrate GPG private keys over network connectivity, posing a significant risk to user data confidentiality. It is imperative for users and administrators to be aware of this issue and take the necessary precautions to mitigate the associated risks.