UBUNTU-CVE-2021-46144
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-46144
UBUNTU-CVE-2021-46144
Summary:
Details: Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.
References: https://ubuntu.com/security/CVE-2021-46144, https://github.com/roundcube/roundcubemail/commit/8894fddd59b770399eed4ef8d4da5773913b5bf0, https://github.com/roundcube/roundcubemail/commit/b2400a4b592e3094b6c84e6000d512f99ae0eed8, https://roundcube.net/news/2021/12/30/update-1.5.2-released, https://roundcube.net/news/2021/12/30/security-update-1.4.13-released, https://bugs.debian.org/1003027, https://github.com/roundcube/roundcubemail/commit/8894fddd59b770399eed4ef8d4da5773913b5bf0, https://github.com/roundcube/roundcubemail/commit/b2400a4b592e3094b6c84e6000d512f99ae0eed8, https://ubuntu.com/security/notices/USN-5182-1, https://www.cve.org/CVERecord?id=CVE-2021-46144
Affected packages
Package
Name: roundcube
Purl: pkg:deb/ubuntu/[email protected]+dfsg.1-1ubuntu0.1~esm2?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
