CVE-2024-42010 Affecting roundcube package, versions <1.3.6+dfsg.1-1ubuntu0.1~esm8


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
14.76% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1804-ROUNDCUBE-10286855
  • published2 May 2026
  • disclosed5 Aug 2024

Introduced: 5 Aug 2024

CVE-2024-42010  (opens in a new tab)

How to fix?

Upgrade Ubuntu:18.04 roundcube to version 1.3.6+dfsg.1-1ubuntu0.1~esm8 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream roundcube package and not the roundcube package as distributed by Ubuntu. See How to fix? for Ubuntu:18.04 relevant fixed versions and status.

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.