CVE-2023-5631
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 November 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 75.87% probability · 99th percentile
- CISA KEV
- Listed 26 October 2023 · due 16 November 2023
- Weakness
- CWE-79
- Affected
- roundcube/webmail · debian/debian linux · fedoraproject/fedora
- Source
- security@eset.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://roundcube.net/news/2023/10/16/security-update-1.6.4-released, https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15 ; https://nvd.nist.gov/vuln/detail/CVE-2023-5631
References
- http://www.openwall.com/lists/oss-security/2023/11/01/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/01/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/17/2Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079Mailing List, Patch
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31dPatch
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613Patch
- https://github.com/roundcube/roundcubemail/issues/9168Exploit, Issue Tracking
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.15Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.5Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.4Release Notes
- https://lists.debian.org/debian-lts-announce/2023/10/msg00035.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/Mailing List
- https://roundcube.net/news/2023/10/16/security-update-1.6.4-releasedRelease Notes
- https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15Release Notes
- https://www.debian.org/security/2023/dsa-5531Mailing List
- http://www.openwall.com/lists/oss-security/2023/11/01/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/01/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/17/2Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079Mailing List, Patch
- https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31dPatch
- https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613Patch
- https://github.com/roundcube/roundcubemail/issues/9168Exploit, Issue Tracking
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.15Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.5Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.4Release Notes
- https://lists.debian.org/debian-lts-announce/2023/10/msg00035.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/Mailing List
- https://roundcube.net/news/2023/10/16/security-update-1.6.4-releasedRelease Notes
- https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15Release Notes
- https://www.debian.org/security/2023/dsa-5531Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.