CVE-2017-16651 KEV
7.8
HIGH · CVSS 3.1 · EPSS 45.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 45.74% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-552 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2017-11-09 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Roundcube Webmail File Disclosure Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Roundcube / Roundcube Webmail |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| roundcube | webmail |
References
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html
- http://www.securityfocus.com/bid/101793
- https://github.com/roundcube/roundcubemail/issues/6026
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3
- https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10
- https://www.debian.org/security/2017/dsa-4030
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html
- http://www.securityfocus.com/bid/101793
- https://github.com/roundcube/roundcubemail/issues/6026
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3
- https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10
- https://www.debian.org/security/2017/dsa-4030
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-16651
→ the Explorer · watch your stack · NVD