{
  "threat_severity" : "Moderate",
  "public_date" : "2025-12-18T04:54:13Z",
  "bugzilla" : {
    "description" : "roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer",
    "id" : "2423487",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2423487"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-116",
  "details" : [ "Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.", "A flaw was found in Roundcube Webmail. This information disclosure vulnerability resides within the HTML style sanitizer, potentially allowing an attacker to gain unauthorized access to sensitive information. The vulnerability is triggered by improper handling of HTML styles." ],
  "statement" : "This vulnerability is rated Low for Red Hat. The information disclosure flaw in Roundcube Webmail's HTML style sanitizer requires user interaction to exploit, limiting its impact in typical Red Hat deployments.",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-68460\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-68460\nhttps://github.com/roundcube/roundcubemail/commit/08de250fba731b634bed188bbe18d2f6ef3c7571\nhttps://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12" ],
  "name" : "CVE-2025-68460",
  "csaw" : false
}