Insecure Permissions in Roundcube Email Clients by Roundcube
CVE-2018-1000071
7.5HIGH
What is CVE-2018-1000071?
The enigma plugin in Roundcube Webmail versions 1.3.4 and earlier exposes a security flaw due to insecure permissions. This vulnerability allows malicious actors to potentially exfiltrate GPG private keys over network connectivity, posing a significant risk to user data confidentiality. It is imperative for users and administrators to be aware of this issue and take the necessary precautions to mitigate the associated risks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved