CVE-2014-9587: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
Other sources
Version 1.0.4 of Roundcube [1] contains a security fix: ... Security: Fix possible CSRF attacks to some address book operations as well as to the ACL and Managesieve plugins. ...
Upstream commit: https://github.com/roundcube/roundcubemail/commit/376cbfd4f2dfcf455717409b70d9d056cbeb08b1
[1]: http://roundcube.net/news/2014/12/18/update-1.0.4-released/
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9587?
CVE-2014-9587 is rated as a high severity vulnerability due to its potential for unauthorized access and actions on behalf of users.
How do I fix CVE-2014-9587?
To fix CVE-2014-9587, upgrade Roundcube Webmail to version 1.0.4 or later.
Which versions of Roundcube are affected by CVE-2014-9587?
CVE-2014-9587 affects all versions of Roundcube Webmail prior to 1.0.4.
What types of attacks exploit CVE-2014-9587?
CVE-2014-9587 can be exploited through multiple cross-site request forgery (CSRF) attacks.
What components are related to CVE-2014-9587 vulnerabilities?
CVE-2014-9587 is related to address book operations, ACLs, and the Managesieve plugins in Roundcube Webmail.