Skip to content

Releases: roundcube/roundcubemail

Roundcube Webmail 1.4.10

27 Dec 22:02
1.4.10
Compare
Choose a tag to compare

This is a service and security update to the stable version 1.4 of Roundcube Webmail.
It contains a fix for a recently reported stored XSS vulnerability as well a small number
of general improvements from our issue tracker. See the full changelog below.

Security fix

  • Stored cross-site scripting (XSS) via HTML or plain text messages with malicious content [CVE-2020-35730]

Credits for this finding go to Alex Birnberg.

This version is considered stable and we recommend to update all productive installations
of Roundcube with it. Please do backup your data before updating!

CHANGELOG

  • Fix extra angle brackets in In-Reply-To header derived from mailto: params (#7655)
  • Fix folder list issue when special folder is a subfolder (#7647)
  • Fix Elastic's folder subscription toggle in search result (#7653)
  • Fix state of subscription toggle on folders list after changing folder state from the search result (#7653)
  • Security: Fix cross-site scripting (XSS) via HTML or plain text messages with malicious content

Roundcube Webmail 1.3.16

27 Dec 21:56
1.3.16
Compare
Choose a tag to compare

This is a security update to the LTS version 1.3.
It fixes a recently reported stored cross-site scripting (XSS)
vulnerability via HTML or plain text messages with malicious content [CVE-2020-35730].

Credits for this finding go to Alex Birnberg.

This version in considered stable and we strongly recommend to update all productive
installations of Roundcube 1.3.x with it. Please do backup your data before updating!

Roundcube Webmail 1.2.13

27 Dec 21:52
1.2.13
Compare
Choose a tag to compare

This is a security update to the LTS version 1.2.
It fixes a recently reported stored cross-site scripting (XSS)
vulnerability via HTML or plain text messages with malicious content [CVE-2020-35730].

Credits for this finding go to Alex Birnberg.

We strongly recommend to update all productive installations of Roundcube 1.2.x
if you cannot upgrade to a more recent version. Please do backup your data before updating!

Roundcube Webmail 1.4.9

27 Sep 19:07
1.4.9
Compare
Choose a tag to compare

This is a service update to the stable version 1.4 of Roundcube Webmail.
It contains fixes and general improvements from our issue tracker, mainly related to email composition and UI oddities in Elastic skin and with the TinyMCE richtext editor. See the full changelog below.

This version is considered stable and we recommend to update all productive installations of Roundcube with it.
Please do backup your data before updating!

CHANGELOG

  • Fix HTML editor in latest Chrome 85.0.4183.102, update to TinyMCE 4.9.11 (#7615)
  • Add missing localization for some label/legend elements in userinfo plugin (#7478)
  • Fix importing birthday dates from Gmail vCards (BDAY:YYYYMMDD)
  • Fix restoring Cc/Bcc fields from local storage (#7554)
  • Fix jstz.min.js installation, bump version to 1.0.7
  • Fix incorrect PDO::lastInsertId() use in sqlsrv driver (#7564)
  • Fix link to closure compiler in bin/jsshrink.sh script (#7567)
  • Fix bug where some parts of a message could have been missing in a reply/forward body (#7568)
  • Fix empty space on mail printouts in Chrome (#7604)
  • Fix empty output from HTML5 parser when content contains XML tag (#7624)
  • Fix scroll jump on key press in plain text mode of the HTML editor (#7622)
  • Fix so autocompletion list does not hide on scroll inside it (#7592)

Roundcube Webmail 1.4.8

10 Aug 19:20
1.4.8
Compare
Choose a tag to compare

This is a service and security update to the stable version 1.4 of Roundcube Webmail.
It contains fixes for recently reported security vulnerabilities as well a small number of general improvements from our issue tracker. See the full changelog below.

Security fixes

  • Fix potential XSS issue in HTML editor of the identity signature input
  • Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]
  • Fix cross-site scripting (XSS) via HTML messages with malicious math content

Credits for the latter two findings go to Łukasz Pilorz from Pentesters.

This version is considered stable and we recommend to update all productive installations of Roundcube with it.
Please do backup your data before updating!

CHANGELOG

  • Managesieve: Fix too-small input field in Elastic when using custom headers (#7498)
  • Fix support for an error as a string in message_before_send hook (#7475)
  • Elastic: Fix redundant scrollbar in plain text editor on mail reply (#7500)
  • Elastic: Fix deleted and replied+forwarded icons on messages list (#7503)
  • Managesieve: Allow angle brackets in out-of-office message body (#7518)
  • Fix bug in conversion of email addresses to mailto links in plain text messages (#7526)
  • Fix format=flowed formatting on plain text part derived from the HTML content (#7504)
  • Fix incorrect rewriting of internal links in HTML content (#7512)
  • Fix handling links without defined protocol (#7454)
  • Fix paging of search results on IMAP servers with no SORT capability (#7462)
  • Fix detecting special folders on servers with both SPECIAL-USE and LIST-STATUS (#7525)
  • Security: Fix potential XSS issue in HTML editor of the identity signature input (#7507)
  • Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]
  • Security: Fix cross-site scripting (XSS) via HTML messages with malicious math content

Roundcube Webmail 1.3.15

10 Aug 19:17
1.3.15
Compare
Choose a tag to compare

This is a security update to the LTS version 1.3.
It fixes two recently reported cross-site scripting (XSS) vulnerabilities via HTML messages with malicious svg and math contents.

Credits for these findings go to Łukasz Pilorz from Pentesters.

This version in considered stable and we strongly recommend to update all productive installations of Roundcube 1.3.x with it.
Please do backup your data before updating!

Roundcube Webmail 1.2.12

10 Aug 19:13
1.2.12
Compare
Choose a tag to compare

This is a security update to the LTS version 1.2.
It fixes two recently reported cross-site scripting (XSS) vulnerabilities via HTML messages with malicious svg and math contents.

Credits for these findings go to Łukasz Pilorz from Pentesters.

We strongly recommend to update all productive installations of Roundcube 1.2.x if you cannot upgrade to a more recent version.
Please do backup your data before updating!

Roundcube Webmail 1.4.7

05 Jul 20:16
1.4.7
Compare
Choose a tag to compare

This is a service and security update to the stable version 1.4 of Roundcube Webmail.
It contains a fix for recently reported security vulnerability as well a small number of general improvements from our issue tracker. See the full changelog below.

Security fix

Prevent cross-site scripting (XSS) via HTML messages with malicious svg/namespace (CVE-2020-15562)

Credits for this finding go to SSD Secure Disclosure.

This version is considered stable and we recommend to update all productive installations of Roundcube with it. Please do backup your data before updating!

CHANGELOG

  • Fix bug where subfolders of special folders could have been duplicated on folder list
  • Increase maximum size of contact jobtitle and department fields to 128 characters
  • Fix missing newline after the logged line when writing to stdout (#7418)
  • Elastic: Fix context menu (paste) on the recipient input (#7431)
  • Fix problem with forwarding inline images attached to messages with no HTML part (#7414)
  • Fix problem with handling attached images with same name when using database_attachments/redundant_attachments (#7455)
  • Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace

Roundcube Webmail 1.3.14

05 Jul 20:14
1.3.14
Compare
Choose a tag to compare

This is a security update to the LTS version 1.3.
It fixes a recently reported cross-site scripting (XSS) vulnerability via HTML messages with malicious svg/namespace (CVE-2020-15562).

Credits for this finding go to SSD Secure Disclosure.

This version in considered stable and we strongly recommend to update all productive
installations of Roundcube 1.3.x with it. Please do backup your data before updating!

Roundcube Webmail 1.2.11

05 Jul 20:12
1.2.11
Compare
Choose a tag to compare

This is a security update to the LTS version 1.2.
It fixes a recently reported cross-site scripting (XSS) vulnerability via HTML messages with malicious svg/namespace (CVE-2020-15562).

Credits for this finding go to SSD Secure Disclosure.

We strongly recommend to update all productive installations of Roundcube 1.2.x
if you cannot upgrade to a more recent version. Please do backup your data before updating!