{
  "id": "CVE-2017-16651",
  "url": "https://spydr.io/cve/CVE-2017-16651",
  "published": "2017-11-09T14:29:00.267Z",
  "modified": "2026-06-17T01:09:37.363Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.45742,
  "epss_percentile": 0.9877,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Roundcube Webmail File Disclosure Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2017-16651"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "roundcube",
    "debian"
  ],
  "products": [
    "roundcube webmail",
    "debian linux"
  ],
  "cwes": [
    "CWE-552"
  ],
  "description": "Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/101793",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/issues/6026",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.1.10",
      "tags": [
        "Issue Tracking",
        "Release Notes",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.2.7",
      "tags": [
        "Issue Tracking",
        "Release Notes",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.3.3",
      "tags": [
        "Issue Tracking",
        "Release Notes",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.debian.org/security/2017/dsa-4030",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-16651",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2017-16651",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
