Hide Forgot
Enigma plugin in roundcube installation running on nginx web server is vulnerable to insecure permissions due to which a remote attacker is able to exfiltrate user's password protected secret GPG key file using a specially crafted URL. Affected versions: before 1.3.4 References: https://github.com/roundcube/roundcubemail/issues/6173 https://www.legacysecuritygroup.com/cve/references/02122018-roundcube-enigma.txt
Created roundcubemail tracking bugs for this issue: Affects: epel-all [bug 1549056] Affects: fedora-all [bug 1549055]
1/ Fedora package don't use .htacess, but protect the directory for both httpd and nginx 2/ The enigma plugin use /var/lib/roundcubemail/enigma which is outside the web tree