Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/98445 | Third Party Advisory VDB Entry |
https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 | Exploit Third Party Advisory |
https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 | Release Notes Vendor Advisory |
https://security.gentoo.org/glsa/201707-11 | Third Party Advisory |
http://www.securityfocus.com/bid/98445 | Third Party Advisory VDB Entry |
https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 | Exploit Third Party Advisory |
https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 | Release Notes Vendor Advisory |
https://security.gentoo.org/glsa/201707-11 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/98445 - Third Party Advisory, VDB Entry | |
References | () https://github.com/ilsani/rd/tree/master/security-advisories/web/roundcube/cve-2017-8114 - Exploit, Third Party Advisory | |
References | () https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 - Release Notes, Vendor Advisory | |
References | () https://security.gentoo.org/glsa/201707-11 - Third Party Advisory |
Information
Published : 2017-04-29 19:59
Updated : 2024-11-21 03:33
NVD link : CVE-2017-8114
Mitre link : CVE-2017-8114
CVE.ORG link : CVE-2017-8114
JSON object : View
Products Affected
roundcube
- webmail
CWE
CWE-269
Improper Privilege Management