Fix XSS vulnerability in post-processing of sanitized HTML content
[CVE-2024-42009]
Fix XSS vulnerability in serving of attachments other than HTML or SVG
[CVE-2024-42008]
Fix information leak (access to remote content) via insufficient CSS
filtering [CVE-2024-42010]
- https://bugs.mageia.org/show_bug.cgi?id=33460
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.8
- https://www.cve.org/CVERecord?id=CVE-2024-42010
- https://www.cve.org/CVERecord?id=CVE-2024-42009
- https://www.cve.org/CVERecord?id=CVE-2024-42008
- 9/core/roundcubemail-1.6.8-1.mga9
Get the latest Linux and open source security news straight to your inbox.