CyberzSOC

Applicability
← Back to CVE-2020-35730

CVE-2020-35730

CVSS 6.1 In CISA KEV Roundcube

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2025-11-21
1 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-17
12 affected 12 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-10-21
1 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (22)

Product Status Versions Remediation Source
red_hat_products Red Hat · All currently supported Red Hat products not affected vulnerable code not present no version stated not applicable csaf_redhat
https://github.com/roundcube/roundcubemail affected < d15f5847bd30d4568c6f3a205dcccc100936a518 vendor fix → d15f5847bd30d4568c6f3a205dcccc100936a518 osv
https://github.com/roundcube/roundcubemail affected >= 854aa7f35f6ed963033e2c0c4735852af7eca21b, < ee2022ab5189cb1879280e04f235dbc08345f6d4 vendor fix → ee2022ab5189cb1879280e04f235dbc08345f6d4 osv
https://github.com/roundcube/roundcubemail affected >= 9291b74675e83c04d5365e010ba5186e672732fb, < 5203a85c92aad4a05b26cda784499eac028dfb83 vendor fix → 5203a85c92aad4a05b26cda784499eac028dfb83 osv
https://github.com/roundcube/roundcubemail affected < 54bf3d0d1acba03db785d16bb53564e417c3883e vendor fix → 54bf3d0d1acba03db785d16bb53564e417c3883e osv
https://github.com/roundcube/roundcubemail affected < 4efec49a46a3f4aab58f606d06b669b6498a0811 vendor fix → 4efec49a46a3f4aab58f606d06b669b6498a0811 osv
https://github.com/roundcube/roundcubemail affected < 9b69cce641a8c34c7efcb34628287d4fadf7bbaf vendor fix → 9b69cce641a8c34c7efcb34628287d4fadf7bbaf osv
https://github.com/roundcube/roundcubemail affected >= 854aa7f35f6ed963033e2c0c4735852af7eca21b, < 54bf3d0d1acba03db785d16bb53564e417c3883e vendor fix → 54bf3d0d1acba03db785d16bb53564e417c3883e osv
https://github.com/roundcube/roundcubemail affected >= fdbdaec9989998b2a378619273f9fb60e6ad6879, < 4efec49a46a3f4aab58f606d06b669b6498a0811 vendor fix → 4efec49a46a3f4aab58f606d06b669b6498a0811 osv
roundcube affected < 1.2.13 vendor fix → 1.2.13 osv BIT-roundcube-2020-35730
roundcube affected >= 1.3.0, < 1.3.16 vendor fix → 1.3.16 osv BIT-roundcube-2020-35730
roundcube affected >= 1.4.0, < 1.4.10 vendor fix → 1.4.10 osv BIT-roundcube-2020-35730
https://github.com/roundcube/roundcubemail fixed d15f5847bd30d4568c6f3a205dcccc100936a518 vendor fix → d15f5847bd30d4568c6f3a205dcccc100936a518 osv
https://github.com/roundcube/roundcubemail fixed ee2022ab5189cb1879280e04f235dbc08345f6d4 vendor fix → ee2022ab5189cb1879280e04f235dbc08345f6d4 osv
https://github.com/roundcube/roundcubemail fixed 5203a85c92aad4a05b26cda784499eac028dfb83 vendor fix → 5203a85c92aad4a05b26cda784499eac028dfb83 osv
https://github.com/roundcube/roundcubemail fixed 9b69cce641a8c34c7efcb34628287d4fadf7bbaf vendor fix → 9b69cce641a8c34c7efcb34628287d4fadf7bbaf osv
https://github.com/roundcube/roundcubemail fixed 54bf3d0d1acba03db785d16bb53564e417c3883e vendor fix → 54bf3d0d1acba03db785d16bb53564e417c3883e osv
https://github.com/roundcube/roundcubemail fixed 4efec49a46a3f4aab58f606d06b669b6498a0811 vendor fix → 4efec49a46a3f4aab58f606d06b669b6498a0811 osv
roundcube fixed 1.2.13 vendor fix → 1.2.13 osv BIT-roundcube-2020-35730
roundcube fixed 1.3.16 vendor fix → 1.3.16 osv BIT-roundcube-2020-35730
roundcube fixed 1.4.10 vendor fix → 1.4.10 osv BIT-roundcube-2020-35730
n/a/n/a n/a · n/a affected no version stated vendor label: all versions none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.