CVE-2018-1000071

HIGH

roundcube <1.3.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/roundcube/roundcubemail/issues/6173

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (1)
roundcube/webmail < 1.3.4
Published Mar 13, 2018
Tracked Since Feb 18, 2026