
Roundcube Webmail 1.6.14 がリリース:任意ファイル書き込みなど複数の深刻な欠陥を修正 https://iototsecnews.jp/2026/03/24/roundcube-webmail-security-updates-patches-multiple-critical-vulnerabilities/ 今回の脆弱性 CVE-2025-24708/CVE-2025-24709 などの主な原因は、セッション・ハンドラにおけるデータの不適切なデシリアライズ処理にあります。それにより、認証を受けていない第三者が悪意の命令を送り込み、サーバ上で任意のファイルを操作できる状態になっていました。また、パスワード変更時のロジック不備や、外部リソースの読み込み制限の不足といった、実装上の細かなミスが重なったことも、被害を広げる要因になり得ます。ご利用のチームは、ご注意ください。 #CVE202524708 #CVE202524709 #Roundcube #Vulnerability #Webmail
Post summary
Roundcube Webmail 1.6.14 release addresses CVE-2025-24708 and CVE-2025-24709, detailing improper deserialization that allowed unauthenticated attackers to perform arbitrary file operations, with the patch and release information clearly provided.
