VDB
CVE-2017-8114
CVE-2017-8114
PUBLISHED
CVSS 8.800000190734863 HIGH
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
EPSS 3.47% · 88.6th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.47%
88.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | roundcube | 0, 1.1.2+dfsg.1-5, 1.1.4+dfsg.1-1 |
Timeline
- CVE Published
- Nov 12, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 16, 2023 EPSS Score
- Sep 18, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-8114 third-party-advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.5 third-party-advisory
- https://github.com/roundcube/roundcubemail/commit/6e054a37d13dc3772d0aa454a32d5dc3bdcc7003 third-party-advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.9 third-party-advisory
- https://github.com/roundcube/roundcubemail/commit/10b227d70a03e33682aaaa0138e84f9256f3cd50 third-party-advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.11 third-party-advisory
- https://github.com/roundcube/roundcubemail/commit/271426429bfbb5b63e6dec91b1e4780e8ef1c67e third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-8114 third-party-advisory