Candidate: CVE-2020-12626 PublicDate: 2020-05-04 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12626 https://github.com/roundcube/roundcubemail/pull/7302 https://github.com/roundcube/roundcubemail/commit/9bbda422ff0b782b81de59c86994f1a5fd93f8e6 https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4 https://github.com/roundcube/roundcubemail/releases/tag/1.4.4 Description: An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959142 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_roundcube: upstream_roundcube: released (1.4.4+dfsg.1-1) precise/esm_roundcube: DNE trusty_roundcube: ignored (out of standard support) trusty/esm_roundcube: DNE xenial_roundcube: ignored (end of standard support, was needed) bionic_roundcube: needed eoan_roundcube: ignored (reached end-of-life) focal_roundcube: needed groovy_roundcube: not-affected (1.4.4+dfsg.1-1) hirsute_roundcube: not-affected (1.4.4+dfsg.1-1) impish_roundcube: not-affected (1.4.4+dfsg.1-1) jammy_roundcube: not-affected (1.4.4+dfsg.1-1) devel_roundcube: not-affected (1.4.4+dfsg.1-1)