Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DLA-3435-1 Moderate: Rainloop XSS Security Issues

debian lts
Calendar Grey May 27, 2023
Dist Debian Esm H88
Ubuntu LTS Advisory USA-4820-1 highlights vulnerabilities in rainloop's security features and urges users to apply patches. Find out more.
Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase leak

Summary

CVE-2019-13389

It was discovered that RainLoop Webmail lacked XSS protection
mechanisms such as xlink:href validation, the X-XSS-Protection
header, and the Content-Security-Policy header.

CVE-2022-29360

Simon Scannell discovered that RainLoop's Email Viewer allows XSS
via a crafted text/html email message.

For Debian 10 buster, these problems have been fixed in version
1.12.1-2+deb10u1.

We recommend that you upgrade your rainloop packages.

For the detailed security status of rainloop please refer to
its security tracker page at:


Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: rainloop
Version: 1.12.1-2+deb10u1
CVE ID: CVE-2019-13389 CVE-2022-29360
Debian Bug: 1004548

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here