Candidate: CVE-2020-16145 PublicDate: 2020-08-12 13:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16145 https://github.com/roundcube/roundcubemail/commit/a71bf2e8d4a64ff2c83fdabc1e8cb0c045a41ef4 (1.4.8) https://github.com/roundcube/roundcubemail/commit/d44ca2308a96576b88d6bf27528964d4fe1a6b8b (1.3.15) https://github.com/roundcube/roundcubemail/commit/589d36010048300ed39f4887aab1afd3ae98d00e (1.2.12) https://github.com/roundcube/roundcubemail/commit/a71bf2e8d4a64ff2c83fdabc1e8cb0c045a41ef4 https://github.com/roundcube/roundcubemail/releases/tag/1.4.8 Description: Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=968216 Priority: medium Discovered-by: Lukasz Pilorz Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/589d36010048300ed39f4887aab1afd3ae98d00e (1.2.x) upstream: https://github.com/roundcube/roundcubemail/commit/d44ca2308a96576b88d6bf27528964d4fe1a6b8b (1.3.x) upstream: https://github.com/roundcube/roundcubemail/commit/a71bf2e8d4a64ff2c83fdabc1e8cb0c045a41ef4 (1.4.x) upstream_roundcube: released (1.2.12, 1.3.15, 1.4.8) precise/esm_roundcube: DNE trusty_roundcube: ignored (out of standard support) trusty/esm_roundcube: DNE xenial_roundcube: needed bionic_roundcube: needed focal_roundcube: needed impish_roundcube: not-affected (1.4.11+dfsg.1-4) jammy_roundcube: not-affected (1.5.0+dfsg.1-2) devel_roundcube: not-affected (1.5.0+dfsg.1-2)