CVE Vulnerabilities

CVE-2017-8114

Improper Privilege Management

Published: Apr 29, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
WebmailRoundcube*1.0.11 (excluding)
WebmailRoundcube1.1.0 (including)1.1.9 (excluding)
WebmailRoundcube1.2.0 (including)1.2.5 (excluding)
RoundcubeUbuntuartful*
RoundcubeUbuntuesm-apps/xenial*
RoundcubeUbuntuprecise*
RoundcubeUbuntutrusty*
RoundcubeUbuntuupstream*
RoundcubeUbuntuxenial*
RoundcubeUbuntuyakkety*
RoundcubeUbuntuzesty*

Potential Mitigations

References