[Japanese]

JVNDB-2009-000071

Roundcube Webmail vulnerable to cross-site request forgery

Overview

Roundcube Webmail provided by Roundcube Webmail Project contains a cross-site requesst forgery vulnerability.

Roundcube Webmail is an open source webmail client from the Roundcube Webmail Project. Roundcube Webmail contains a cross-site request forgery vulnerability.

This issue is different from JVN#33820033 and JVN#75694913.

Shuya Ueki reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 2.6 (Low) [IPA Score]
  • Access Vector: Network
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products

Roundcube Webmail Project
  • Roundcube Webmail 0.2.2 and earlier
Impact

An attacker may be able to alter the user information within Roundcube Webmail.
Solution

[Update the Software]
Apply the latest update provided by the developer.
Vendor Information

Roundcube Webmail Project
References

  1. JVN : JVN#72974205
  2. National Vulnerability Database (NVD) : CVE-2009-4076
  3. Common Vulnerabilities and Exposures (CVE) : CVE-2009-4076
  4. Secunia Advisory : SA37235
  5. OPEN SOURCE VULNERABILITY DATABASE (OSVDB) : 59661
  6. Common Weakness Enumeration (CWE) : Cross-Site Request Forgery (CWE-352) [IPA Evaluation]
Revision History

[2009/11/04]
  Web page published


Date Public2009/11/04
Date First Published2009/11/04
Date Last Updated2009/11/04