CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-42008

unknowncovered by 1 sourcefirst seen 2024-08-09
On August 4, 2024, Roundcube released patches for critical vulnerabilities CVE-2024-42008 and CVE-2024-42009 affecting its email server. These vulnerabilities allow for indirect remote code injections (XSS) that can, for example, lead to the retrieval of...

CSIRTS triage

What
Roundcube has critical vulnerabilities that allow for indirect remote code injections (XSS).
Who is affected
Deployments of Roundcube email server are affected by these vulnerabilities.
Urgency
Remediation is urgent due to confirmed exploitation and the critical nature of the vulnerabilities.
Action
Users should apply the patches released on August 4, 2024.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2024-42008

Get an email if CVE-2024-42008 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2024-42008

CVE.org record

Embed the live status

CVE-2024-42008 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2024-42008 status](https://www.csirts.com/badge/CVE-2024-42008)](https://www.csirts.com/cve/CVE-2024-42008)