CVE-2017-16651
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Roundcube Webmail File Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 37% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-552
מוצרים מושפעים
roundcube: webmail; debian: debian linux
קישורים
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10 Issue TrackingVendor Advisory
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10 Issue TrackingVendor Advisory
- https://github.com/roundcube/roundcubemail/issues/6026 Issue TrackingPatchThird Party Advisory
- https://github.com/roundcube/roundcubemail/issues/6026 Issue TrackingPatchThird Party Advisory
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclos… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclos… ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/101793 Third Party AdvisoryVDB Entry
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10 Issue TrackingRelease NotesThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7 Issue TrackingRelease NotesThird Party Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3 Issue TrackingRelease NotesThird Party Advisory