CVE-2017-8114: High severity Roundcube Webmail vulnerability
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8114?
CVE-2017-8114 is considered a high severity vulnerability that allows authenticated users to perform arbitrary password resets.
How do I fix CVE-2017-8114?
To fix CVE-2017-8114, upgrade to Roundcube Webmail version 1.0.11 or later, 1.1.9 or later, or 1.2.5 or later.
Which versions of Roundcube Webmail are affected by CVE-2017-8114?
Versions of Roundcube Webmail prior to 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 are affected by CVE-2017-8114.
What causes the vulnerability in CVE-2017-8114?
CVE-2017-8114 is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
Who is impacted by CVE-2017-8114?
Authenticated users of Roundcube Webmail versions prior to the patched versions are impacted by CVE-2017-8114.