learning_curve
Golden Pleskian
Via Plesk, we provide (and so have users that prefer to use) Roundcube Webmail. There's already a lot of very helpful Plesk pages, which we've used previoulsy, to make this even more secure than the default settings it is provided with.
The quickest way to make all these modifications in our case (with Ubuntu) is by editing both the <IfModule mod_headers.c> and <IfModule mod_rewrite.c> sections of this file: /etc/apache2/plesk.conf.d/roundcube.htaccess.inc and then restarting Apache. So far, no problems at all with this
However, when we run independent, rigourous security checks on the webmail sections of domains, we get this one error:
"Indicator of compromise: There is an altered version of a popular JavaScript script or framework"
This ^^ is NOT because of the htaccess modifications, because we've tested with and without these modifications.
We're on the latest release of Plesk 17.8.11 and the Roundcube provided on this is:
Can somebody at Plesk answer / confirm that using this older release may be, the cause of the security error and if so, what are the workarounds and/or what is the intended release date of Plesk's Roundcube 1.3.8 (or 1.4 which is due soon
)
The quickest way to make all these modifications in our case (with Ubuntu) is by editing both the <IfModule mod_headers.c> and <IfModule mod_rewrite.c> sections of this file: /etc/apache2/plesk.conf.d/roundcube.htaccess.inc and then restarting Apache. So far, no problems at all with this
However, when we run independent, rigourous security checks on the webmail sections of domains, we get this one error:
"Indicator of compromise: There is an altered version of a popular JavaScript script or framework"
This ^^ is NOT because of the htaccess modifications, because we've tested with and without these modifications.
We're on the latest release of Plesk 17.8.11 and the Roundcube provided on this is:
However, meanwhile at RoundcubePackage: plesk-roundcube
Status: install ok installed
Priority: extra
Section: web Installed-Size: 25295
Maintainer: Plesk <[email protected]>
Architecture: all Version: 1.3.6-ubuntu18.04.build1708180613.11
Depends: plesk-base (>= 17.8.11), psa (>= 17.8.11), plesk-web-hosting (>= 17.8.11), libapache2-mod-fcgid-psa (>= 2.3.5)
Conffiles: ~~
So... unless Plesk have backported all these updates (if so, please advise) this means that we are two official stable releases and 3 months timewise, behind Roundcube.Update 1.3.8 released. 26 October 2018
We proudly announce the next service release to update the stable version 1.3.
It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot and MySQL 8
Can somebody at Plesk answer / confirm that using this older release may be, the cause of the security error and if so, what are the workarounds and/or what is the intended release date of Plesk's Roundcube 1.3.8 (or 1.4 which is due soon