Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

issues on Roundcube 1.4 #7698

Closed
glraj70 opened this issue Oct 28, 2020 · 3 comments
Closed

issues on Roundcube 1.4 #7698

glraj70 opened this issue Oct 28, 2020 · 3 comments

Comments

@glraj70
Copy link

glraj70 commented Oct 28, 2020

Hello,

I will repost as single issues

Regards,
Rajesh G L

@alecpl
Copy link
Member

alecpl commented Oct 28, 2020

I don't have time to process this now, but in a quick look the report looks quite useless. It describes some general rules mostly about session security and tokens, but does not describe real issues.

@johndoh
Copy link
Contributor

johndoh commented Oct 28, 2020

@glraj70 publishing vulnerability reports in a public forum without first giving devs an opportunity to address those vulnerabilities is not very friendly, you risk handing information to bad actors putting your own installation and others at greater risk. Also as a general rule its best to limit tickets to single issues this makes for easier tracking and management.

In this case the report does not contain much in the way of any actual problems though. It lists 3 potential issues:

  1. Session Hijacking - mitigations already exist for this, see Authentication Bypass via Improper Session Management #7576
  2. Session token in URL - this is part of the CSRF and only used in situations where POST is not practical. IMO this is low risk but mitigations also already exist for this, look at the use_secure_urls config option
  3. Parameter Tampering - I do not understand what issue is being described here

@glraj70
Copy link
Author

glraj70 commented Oct 28, 2020

Hi Johndoh,
Thanks for the reply .
Apologies for posting in public forum. In future i will post as single issues.
I will close this case.
Kindly delete the post from the forum.

@glraj70 glraj70 closed this as completed Oct 28, 2020
@glraj70 glraj70 changed the title Vulnerabilities on Roundcube 1.4 issues on Roundcube 1.4 Oct 28, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants