Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Roundcube flaws allow easy email account compromise (CVE-2024-42009, CVE-2024-42008) #2430

Open
henningwerner opened this issue Aug 13, 2024 · 7 comments

Comments

@henningwerner
Copy link

Thanks for your awesome project! Can you please push new Roundcube version to the repo to close both CVEs.

@myfirstnameispaul
Copy link
Contributor

PR submitted 3 days after the new versions were announced:

#2422

For future reference, you can find open PRs here:

https://github.com/mail-in-a-box/mailinabox/pulls

@dmitridb
Copy link

dmitridb commented Aug 13, 2024

https://github.com/roundcube/roundcubemail/releases/tag/1.6.7

Yet it was back in May with some of these patches

I am now in the process of convincing my clients to switch mailserver solutions since they can't expect something like this to be maintained. I know you even say you don't care about NSA-grade security but these are email servers and the threat model is different here. These are flaws that someone as dumb as a malicious child or even some indiscriminate bot can and will exploit and you've failed to patch in releases like three times now

@matidau
Copy link
Contributor

matidau commented Aug 14, 2024

Just a suggestion, you can fork the current version and merge any of the security updates against the fork, such as this one.

Then on the server change to your fork with git and run mailinabox.

When Josh releases a new version with these included then switch back with git.

@dmitridb
Copy link

thanks this has been patched in #2422

I got a little tripped up at the step where getting that hash is necessary - if anything only because I have access to production mailservers that it would be less than fun to be playing with potentially buggy scripts on. Is that just a sha256sum of the roundcubemail tar.gz file? Seems like there should be a better way of doing that somehow. They provide an asc file for verification instead for example.

@JJJ
Copy link
Contributor

JJJ commented Aug 26, 2024

v70 was tagged August 15 and appears to include this.

See: https://github.com/mail-in-a-box/mailinabox/releases/tag/v70

Recommend to close this issue and PR at #2422.

@matidau
Copy link
Contributor

matidau commented Aug 27, 2024

#2422 is already closed (merged)

@FUADMOHAMED022
Copy link

Thanks for your awesome project! Can you please push new Roundcube version to the repo to close both CVEs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants