From 93a94d33ce2ade727471e9254c21dfbcadf54897 Mon Sep 17 00:00:00 2001 From: willofr Date: Wed, 5 Jan 2022 11:17:31 +0100 Subject: [PATCH 1/2] update roundcube to 1.5.2 (security fix) New roundcube release (1.5.2) where a XSS is addressed: https://roundcube.net/news/2021/12/30/update-1.5.2-released --- webmails/roundcube/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/webmails/roundcube/Dockerfile b/webmails/roundcube/Dockerfile index 54b50e60..a222c514 100644 --- a/webmails/roundcube/Dockerfile +++ b/webmails/roundcube/Dockerfile @@ -39,7 +39,7 @@ RUN set -eu \ && apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false \ && rm -rf /var/lib/apt/lists -ENV ROUNDCUBE_URL https://github.com/roundcube/roundcubemail/releases/download/1.5.1/roundcubemail-1.5.1-complete.tar.gz +ENV ROUNDCUBE_URL https://github.com/roundcube/roundcubemail/releases/download/1.5.2/roundcubemail-1.5.2-complete.tar.gz ENV CARDDAV_URL https://github.com/mstilkerich/rcmcarddav/releases/download/v4.3.0/carddav-v4.3.0.tar.gz RUN set -eu \ From f330a518fa5742a3c30373bb0f4e743cd9ce9a17 Mon Sep 17 00:00:00 2001 From: willofr Date: Wed, 5 Jan 2022 11:23:31 +0100 Subject: [PATCH 2/2] Create 2141.bugfix --- towncrier/newsfragments/2141.bugfix | 1 + 1 file changed, 1 insertion(+) create mode 100644 towncrier/newsfragments/2141.bugfix diff --git a/towncrier/newsfragments/2141.bugfix b/towncrier/newsfragments/2141.bugfix new file mode 100644 index 00000000..2ead7ce3 --- /dev/null +++ b/towncrier/newsfragments/2141.bugfix @@ -0,0 +1 @@ +Update roundcube to 1.5.2 to fixe an XSS