CVE Vulnerabilities

CVE-2017-8114

Improper Privilege Management

Published: Apr 29, 2017 | Modified: Sep 27, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Webmail Roundcube * 1.0.11 (excluding)
Webmail Roundcube 1.1.0 (including) 1.1.9 (excluding)
Webmail Roundcube 1.2.0 (including) 1.2.5 (excluding)
Roundcube Ubuntu artful *
Roundcube Ubuntu esm-apps/xenial *
Roundcube Ubuntu precise *
Roundcube Ubuntu trusty *
Roundcube Ubuntu upstream *
Roundcube Ubuntu xenial *
Roundcube Ubuntu yakkety *
Roundcube Ubuntu zesty *

Potential Mitigations

References