CVE-2017-16651: Roundcube Webmail File Disclosure Vulnerability
Last updated 13 January 2025
Other sources
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and task=settings&action=upload-display&from=timezone requests.
Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1+deb11u4Fixed in 1.6.5+dfsg-1+deb12u4Fixed in 1.6.9+dfsg-2 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.1.10 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.2.7 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.3.3
Event History
Frequently Asked Questions
What is the vulnerability ID for the Roundcube Webmail file disclosure vulnerability?
The vulnerability ID for the Roundcube Webmail file disclosure vulnerability is CVE-2017-16651.
What is the severity of CVE-2017-16651?
The severity of CVE-2017-16651 is high with a CVSS score of 7.8.
Which versions of Roundcube Webmail are affected by CVE-2017-16651?
Roundcube Webmail versions before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 are affected by CVE-2017-16651.
How can an attacker exploit CVE-2017-16651?
An attacker can exploit CVE-2017-16651 by gaining unauthorized access to arbitrary files on the host's filesystem, including configuration files.
Is there a fix available for CVE-2017-16651?
Yes, a fix for CVE-2017-16651 is available. Users should update to Roundcube Webmail version 1.1.10, 1.2.7, or 1.3.3 or later.