CVE Vulnerabilities

CVE-2017-8114

Improper Privilege Management

Published: Apr 29, 2017 | Modified: Sep 27, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Webmail Roundcube * 1.0.11 (excluding)
Webmail Roundcube 1.1.0 (including) 1.1.9 (excluding)
Webmail Roundcube 1.2.0 (including) 1.2.5 (excluding)

Potential Mitigations

References