• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Resolved Roundcube CVE 2024 - when does Plesk release an update?

For whatever reason, Plesk seem to always be way behind with Roundcube updates (see my own thread here, on a different Roundcube matter, but there's previous threads to this too, again, all related to Roundcube / Plesk) This, despite Roundcube perhaps being, the most popular e-mail service for Plesk users. Good to see that you've posted this @smaxxx and looking forwards to a swift reply from Plesk, which hopefully, really should be; Plesk supporting Roundcube 1.6.8, on PHP 8.3, on the next Obsdian release, but with legacy support for older OS / older Roundcube releases - all of the latter, at user's own risk.
 
Hello, everyone. Our team is already actively working on updating RoundCube to 1.6.8. We are planning to release the hotfix in the upcoming week. We would like to thank you in advance for your patience in the meantime.
 
For those like me who cannot wait, here are all the 3 fixes for the CVE's to fix on your own risk, as always..hf!
  • Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009]
  • Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008]
  • Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010]
 
Hello, everyone. Our team is already actively working on updating RoundCube to 1.6.8. We are planning to release the hotfix in the upcoming week. We would like to thank you in advance for your patience in the meantime.

Please release a hotfix for Plesk Obsidian 18.0.63 and Plesk Obsidian 18.0.62. We don't want to install 18.0.63 yet, as it's just been released.
 
Hello, everyone. I just wanted to inform you that we released a hotfix with RoundCube vulnerability patches and version update to 1.6.8. Plesk Obsidian 18.0.63 Update 1:


We understand that some of you are still using Plesk 18.0.62 given that the new version was recently released. However, after thorough consideration and taking into account that we have not observed any major issues with Plesk Obsidian 18.0.63, the hotfix was released only for the current version and we would advise to upgrade.
 
Back
Top