DLA-3435-1

Source
https://storage.googleapis.com/debian-osv/dla-osv/DLA-3435-1.json
Published
2023-05-28T00:00:00Z
Modified
2023-06-28T06:26:58.130117Z
Details

Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase leak.

  • CVE-2019-13389 It was discovered that RainLoop Webmail lacked XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
  • CVE-2022-29360 Simon Scannell discovered that RainLoop's Email Viewer allows XSS via a crafted text/html email message.

For Debian 10 buster, these problems have been fixed in version 1.12.1-2+deb10u1.

We recommend that you upgrade your rainloop packages.

For the detailed security status of rainloop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/rainloop

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

References

Affected packages

Debian:10 / rainloop

Source Details

Package Name
rainloop

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.12.1-2+deb10u1

Affected versions

1.*

1.12.1-2