#VU31183 Information disclosure in Roundcube - CVE-2018-19205
Published: November 12, 2018 / Updated: July 17, 2020
Roundcube
Roundcube
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.