Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues.

Administrators using Roundcube 1.6.x or 1.7.x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend.

Security researcher nept1337 reported the issue. Successful exploitation could allow an attacker to execute commands within the affected Roundcube environment, posing a direct risk to the webmail server and potentially to other systems reachable from it.

Roundcube is widely used as a browser-based interface for email services. Because it processes email content, connects to IMAP servers, and may integrate with LDAP directories, Sieve filters, and spam-management tools, a compromise can provide a useful entry point into an organization’s messaging infrastructure.

Roundcube 1.6.18 and 1.7.3 Released With Fix

An RCE vulnerability in this environment could enable attackers to steal mail data, establish persistence, or pivot to internal services. The release also fixes SSRF filter bypass vulnerabilities in Roundcube’s local URL validation logic.

SSRF occurs when an attacker can make an application send requests to locations chosen by the attacker, including internal services that are not publicly accessible. One bypass involved special local address ranges, including 100.64.0.0/10 and fe80::/10.

Another used crafted nip.io and sslip.io hostnames that could evade the is_local_url() check. Dmytro Ivanenko and Milan Hoppe reported the issues.

In a practical scenario, an attacker could exploit an SSRF vulnerability to request an internal administrative page, a cloud metadata endpoint, or a service running only on a private network interface.

The impact depends on network design and outbound access controls. However, webmail servers with broad internal connectivity may face greater exposure.

Other fixes in the two releases include an LDAP filter injection flaw, arbitrary Sieve script injection, IMAP command injection, stored XSS in the “Add to address book” action, and HTML/CSS sanitization bypasses.

Roundcube also fixed a password-driver issue that could expose an authentication token to a user-controlled host. Researchers credited for the broader set of findings include Zach Hanley of Horizon3.ai, Paulos Yibelo of pwn.ai, vectrain, and meifukun.

Affected deployments include Roundcube 1.6.x versions earlier than 1.6.18 and 1.7.x versions earlier than 1.7.3. Roundcube has not reported confirmed in-the-wild exploitation in its advisory. However, the range and severity of the patched bugs make rapid remediation important.

Administrators should upgrade to Roundcube 1.6.18 or 1.7.3, depending on their release branch. They should also review whether the markasjunk plugin is required and disable it if it is not in use.

Organizations can further reduce SSRF risk by restricting outbound connections from the Roundcube host and limiting its access to sensitive internal services.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.