« Volver al listado

CVE-2023-5631

Estado: AnalizadaMedia (5.4)⚠ Explotación activa

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker

to load arbitrary JavaScript code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

XSS almacenado (CWE-79) en Roundcube vía SVG en email permite ejecución de JavaScript arbitrario en navegador (T1189, AV:N). Acceso a datos del cliente como efecto secundario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5631",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5631",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-11-15T16:39:21.592115Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@eset.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@eset.com",
      "affectedData": [
        {
          "repo": "https://github.com/roundcube/roundcubemail",
          "vendor": "Roundcube",
          "product": "Roundcubemail",
          "versions": [
            {
              "status": "affected",
              "version": "1.6.0",
              "lessThan": "1.6.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.5.0",
              "lessThan": "1.5.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.4.0",
              "lessThan": "1.5.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "1.6.4"
            },
            {
              "status": "unaffected",
              "version": "1.5.5"
            },
            {
              "status": "unaffected",
              "version": "1.5.15"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-18T15:15:08.727",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/01/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/01/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/17/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079",
      "tags": [
        "Mailing List",
        "Patch"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d",
      "tags": [
        "Patch"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613",
      "tags": [
        "Patch"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/issues/9168",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.4.15",
      "tags": [
        "Release Notes"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.5.5",
      "tags": [
        "Release Notes"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.4",
      "tags": [
        "Release Notes"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/",
      "tags": [
        "Mailing List"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://roundcube.net/news/2023/10/16/security-update-1.6.4-released",
      "tags": [
        "Release Notes"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15",
      "tags": [
        "Release Notes"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "https://www.debian.org/security/2023/dsa-5531",
      "tags": [
        "Mailing List"
      ],
      "source": "security@eset.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/01/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/01/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/11/17/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054079",
      "tags": [
        "Mailing List",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/commit/6ee6e7ae301e165e2b2cb703edf75552e5376613",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/issues/9168",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.4.15",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.5.5",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.4",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00035.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LK67Q46OIEGJCRQUBHKLH3IIJTBNGGX4/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://roundcube.net/news/2023/10/16/security-update-1.6.4-released",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2023/dsa-5531",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5631",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@eset.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker\n\nto load arbitrary JavaScript code."
    },
    {
      "lang": "es",
      "value": "Roundcube anterior a 1.4.15, 1.5.x anterior a 1.5.5 y 1.6.x anterior a 1.6.4 permiten almacenar XSS a través de un mensaje de correo electrónico HTML con un documento SVG manipulado debido al comportamiento de program/lib/Roundcube/rcube_washtml.php. Esto podría permitir que un atacante remoto cargue código JavaScript arbitrario."
    }
  ],
  "lastModified": "2026-06-17T06:48:58.673",
  "cisaActionDue": "2023-11-16",
  "cisaExploitAdd": "2023-10-26",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A35A7DC-58C4-43F7-A66C-229B0A409224",
              "versionEndExcluding": "1.4.15"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF32BDE4-0C58-4D19-9E7C-CC0C0B22DF51",
              "versionEndExcluding": "1.5.5",
              "versionStartIncluding": "1.5.0"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBAB5ECE-B692-46C2-A3EF-6BC52E4F3C3B",
              "versionEndExcluding": "1.6.4",
              "versionStartIncluding": "1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46D69DCC-AE4D-4EA5-861C-D60951444C6C"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@eset.com",
  "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability"
}