==================================================================== CERT-Renater Note d'Information No. 2020/VULN376 _____________________________________________________________________ DATE : 09/07/2020 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Roundcube Webmail versions prior to 1.4.7, 1.3.14, 1.2.11. ===================================================================== https://roundcube.net/news/2020/07/05/security-updates-1.4.7-1.3.14-and-1.2.11 _____________________________________________________________________ Security updates 1.4.7, 1.3.14 and 1.2.11 released 05 July 2020 We just published security updates to the stable version 1.4 and the LTS versions 1.3 and 1.2 of Roundcube Webmail. They all contain a recently reported cross-site scripting (XSS) vulnerability. The 1.4.7 release also contains a number of general improvements from our issue tracker. Security fix Prevent cross-site scripting (XSS) via HTML messages with malicious svg/namespace. Credits for this finding go to SSD Secure Disclosure. See the full changelogs in the release notes on the Github download pages for the updated versions 1.4.7, 1.3.14 and 1.2.11. We strongly recommend to update all productive installations of Roundcube with this new versions. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================