CVE-2023-43770: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcubestringreplacer.php behavior.
Other sources
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.3.17+dfsg.1-1~deb10u5Fixed in 1.4.15+dfsg.1-1~deb11u2Fixed in 1.6.5+dfsg-1~deb12u1Fixed in 1.6.6+dfsg-2 - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.3.6+dfsg.1-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.3+dfsg.1-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.5.0+dfsg.1-2ubuntu0.1~ - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.2+dfsg-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.3+dfsg-1 - Upgrade
Upgrade
ubuntu/roundcubeto a version that resolves this vulnerability.Fixed in 1.2~ - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.4.14 - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.5.4 - Upgrade
Upgrade
Roundcubeto a version that resolves this vulnerability.Fixed in 1.6.3 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.3.17+dfsg.1-1~deb10u5 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.4.15+dfsg.1-1~deb11u2 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.5+dfsg-1~deb12u1 - Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.6.6+dfsg-2 - Remove
Remove
Roundcubefrom your environment.Discontinue use of the product (uninstall) if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions if an immediate upgrade is not possible.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Roundcube vulnerability?
The vulnerability ID for this Roundcube vulnerability is CVE-2023-43770.
What is the severity of CVE-2023-43770?
The severity of CVE-2023-43770 is medium.
Which versions of Roundcube are affected by CVE-2023-43770?
Roundcube versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 are affected by CVE-2023-43770.
How does CVE-2023-43770 occur?
CVE-2023-43770 occurs due to XSS in text/plain e-mail messages with crafted links in Roundcube.
How can I fix CVE-2023-43770?
To fix CVE-2023-43770, update Roundcube to version 1.4.14, 1.5.4, or 1.6.3.