CVE-2020-35730
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 July 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 32.69% probability · 98th percentile
- CISA KEV
- Listed 22 June 2023 · due 13 July 2023
- Weakness
- CWE-79
- Affected
- roundcube/webmail · fedoraproject/fedora · debian/debian linux
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://roundcube.net/news/2020/12/27/security-updates-1.4.10-1.3.16-and-1.2.13; https://nvd.nist.gov/vuln/detail/CVE-2020-35730
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491Issue Tracking, Mailing List
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.13Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.16Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.10Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/Mailing List, Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/Mailing List, Release Notes
- https://roundcube.net/download/Product
- https://www.alexbirnberg.com/roundcube-xss.htmlBroken Link
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978491Issue Tracking, Mailing List
- https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.13Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.16Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.10Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCEU4BM5WGIDJWP6Z4PCH62ZMH57QYM2/Mailing List, Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q/Mailing List, Release Notes
- https://roundcube.net/download/Product
- https://www.alexbirnberg.com/roundcube-xss.htmlBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-35730US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.