# \[Security\] Rainloop suffers a security bug

**URL:** https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579
**Category:** Security
**Tags:** security, english
**Created:** [April 21, 2022, 2:25pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579 "2022-04-21T14:25:22Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![nath5394](https://forum.yunohost.org/user_avatar/forum.yunohost.org/nath5394/32/1717_2.png) [@nath5394](https://forum.yunohost.org/u/nath5394)
#### Post date: [April 21, 2022, 2:25pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/1 "2022-04-21T14:25:22Z")

</div>

It seems Rainloop suffers a non fixed security issue.

> **[Unpatched Bug in RainLoop Webmail Could Give Hackers Access to all Emails](https://thehackernews.com/2022/04/unpatched-bug-in-rainloop-webmail-could.html?m=1)**
>
> A new unpatched vulnerability has been disclosed in the RainLoop webmail client that could allow hackers to remotely access all emails.

The version we have is the latest and is affected: `Shipped version: 1.16.0~ynh3`

The only advise is to migrate from Rainloop to SnappyMail… [https://snappymail.eu/](https://snappymail.eu/)  
I open the this topic to discuss what would be best, as I assume that many instances are using Rainloop as their main webmail.

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [April 21, 2022, 6:35pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/2 "2022-04-21T18:35:32Z")

</div>

> “When the email is viewed by the victim, the attacker gains full control over the session of the victim and can steal any of their emails, including those that contain highly sensitive information such as passwords, documents, and password reset links.”

So never open an email from unknown sender.  
Limiting access for visitors, but the yunohost instance uses the same password as the mail, so if the hacker can get the password of the mailbox, the hole instance is compromised.

---

<div class="post-metadata">

### Author: ![tituspijean](https://forum.yunohost.org/user_avatar/forum.yunohost.org/tituspijean/32/3584_2.png) [@tituspijean](https://forum.yunohost.org/u/tituspijean)
#### Post date: [April 21, 2022, 7:22pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/3 "2022-04-21T19:22:19Z")

</div>

I’m pinning this thread at the top of the forum. Thanks for the notice!

Our serial-packager eric is already working on packaging SnappyMail : [YunoHost-Apps/snappymail\_ynh: SnappyMail package for YunoHost (github.com)](https://github.com/YunoHost-Apps/snappymail_ynh).

If RainLoop remains unmaintained upstream, we will most likely flag it as dangerous in the catalog. This depends on a yet-to-be coded feature, cf. [Anti-features draft by Tagadda · Pull Request #1312 · YunoHost/apps (github.com)](https://github.com/YunoHost/apps/pull/1312), [Add Anti-Features in READMEs by Tagadda · Pull Request #1338 · YunoHost/apps (github.com)](https://github.com/YunoHost/apps/pull/1338), and future improvement of the catalog to show such anti-features.

---

<div class="post-metadata">

### Author: ![tituspijean](https://forum.yunohost.org/user_avatar/forum.yunohost.org/tituspijean/32/3584_2.png) [@tituspijean](https://forum.yunohost.org/u/tituspijean)
#### Post date: [April 21, 2022, 7:22pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/4 "2022-04-21T19:22:37Z")

</div>



---

<div class="post-metadata">

### Author: ![Lapineige](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/l/bc79bd/32.png) [@Lapineige](https://forum.yunohost.org/u/Lapineige)
#### Post date: [April 21, 2022, 9:19pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/5 "2022-04-21T21:19:41Z")

</div>

So another workaround in the mid-time is not to use Rainloop and redirect all emails to another email address.

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [April 21, 2022, 11:03pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/6 "2022-04-21T23:03:16Z")

</div>

In fact, I have it installed but rarely use it since I’m using k9mail and thunderbird.

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [April 21, 2022, 11:22pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/7 "2022-04-21T23:22:44Z")

</div>

Rainloop has been removed from the awesome selfhosted list

> <https://github.com/awesome-selfhosted/awesome-selfhosted/pull/2814>
>
> SnappyMail is a fork of RainLoop. 
> The reason for adding it is mainly because R…ainLoop is not developed.It has over 800 issues including some that look like serious security vulnerabilities, e.g:
> https://github.com/RainLoop/rainloop-webmail/issues/2134
> https://github.com/RainLoop/rainloop-webmail/issues/2142
> 
> 
> 
> Thank you for taking the time to work on a PR for Awesome-Selfhosted!
> 
> To ensure your PR is dealt with swiftly please check the following:
> 
> \- \[x\] Submit one item per pull request. This eases reviewing and speeds up inclusion.
> \- \[x\] Format your submission as follows, where \`Demo\` and \`Clients\` are optional.
> Do not add a duplicate \`Source code\` link if it is the same as the main link.
> Keep the short description under 250 characters and use \[sentence case\](https://en.wikipedia.org/wiki/Letter\_case#Sentence\_case)
> for it, even if the project's webpage or readme uses another capitalisation
> such as title case, all caps, small caps or all lowercase.
> \`Demo\` links should only be used for interactive demos, i.e. not video demonstrations.
> \`\`- \[Name\](http://homepage/) - Short description, under 250 characters, sentence case. (\[Demo\](http://url.to/demo), \[Source Code\](http://url.of/source/code), \[Clients\](https://url.to/list/of/related/clients-or-apps)) \`License\` \`Language\` \`\`
> \- \[x\] Additions that depend on proprietary services outside the user's control must be marked \`⚠\`.
> \`\`- \[Name\](http://homepage/) \`⚠\` - Short description, under 250 characters, sentence case. (\[Demo\](http://url.to/demo), \[Source Code\](http://url.of/source/code), \[Clients\](https://url.to/list/of/related/clients-or-apps)) \`License\` \`Language\` \`\`
> \- \[x\] Additions that are not \[Free software\](https://en.wikipedia.org/wiki/Free\_software)
> must be added to \`non-free.md\` and marked \`⊘ Proprietary\`:
> \`\`- \[Name\](http://homepage/) \`⊘ Proprietary\` - Short description, under 250 characters, sentence case. (\[Demo\](http://url.to/demo), \[Source Code\](http://url.of/source/code), \[Clients\](https://url.to/list/of/related/clients-or-apps)) \`Language\` \`\`
> \- \[x\] Additions are inserted preserving alphabetical order.
> \- \[\] Additions are not already listed at any of \[awesome-sysadmin\](https://github.com/n1trux/awesome-sysadmin), \[awesome-analytics\](https://github.com/onurakpolat/awesome-analytics), \[staticgen.com\](https://www.staticgen.com/), \[staticsitegenerators.net\](https://staticsitegenerators.net/).
> \- \[x\] The \`Language\` tag is the main \*\*server-side\*\* requirement for the software. Don't include frameworks or specific dialects.
> \- \[x\] Any license you add is in our \[list of licenses\](https://github.com/awesome-selfhosted/awesome-selfhosted/blob/master/README.md#list-of-licenses).
> \- \[x\] You have searched the repository for any relevant \[issues\](https://github.com/awesome-selfhosted/awesome-selfhosted/issues) or \[PRs\](https://github.com/awesome-selfhosted/awesome-selfhosted/pulls), including closed ones.
> \- \[\] Any category you are creating has the minimum requirement of 3 items.
> If not, your addition may be inserted into \`Misc/Other\`.
> \- \[x\] Any software project you are adding to the list is actively maintained.
> \- \[x\] The pull request title is informative, unlike "Update README.md".
> Suggested titles: "Add aaa to bbb" for adding software aaa to section bbb,
> "Remove aaa from bbb" for removing, "Fix license for aaa", etc.

It has also been removed from other projects.

---

<div class="post-metadata">

### Author: ![nath5394](https://forum.yunohost.org/user_avatar/forum.yunohost.org/nath5394/32/1717_2.png) [@nath5394](https://forum.yunohost.org/u/nath5394)
#### Post date: [April 22, 2022, 5:58am UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/8 "2022-04-22T05:58:53Z")

</div>

For people looking for another webmail app there is also Roundcube.

> **[GitHub - YunoHost-Apps/roundcube\_ynh: Roundcube package for YunoHost](https://github.com/YunoHost-Apps/roundcube_ynh)**
>
> Roundcube package for YunoHost. Contribute to YunoHost-Apps/roundcube\_ynh development by creating an account on GitHub.

Thank you Eric!

---

<div class="post-metadata">

### Author: ![petrus](https://forum.yunohost.org/user_avatar/forum.yunohost.org/petrus/32/407_2.png) [@petrus](https://forum.yunohost.org/u/petrus)
#### Post date: [April 23, 2022, 7:21am UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/9 "2022-04-23T07:21:56Z")

</div>

A sad news…!  
So, the best option now is to uninstall Rainloop ?

About Roundcube, I remember it was really heavy to load on a Raspberry Pi, a long time ago… that’s why I love Rainloop, it’s faster, and it’s less a gas factory 😃

---

<div class="post-metadata">

### Author: ![nath5394](https://forum.yunohost.org/user_avatar/forum.yunohost.org/nath5394/32/1717_2.png) [@nath5394](https://forum.yunohost.org/u/nath5394)
#### Post date: [April 23, 2022, 7:24am UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/10 "2022-04-23T07:24:29Z")

</div>

Yep, we should uninstall Rainloop. Soon, we might have the possibility to switch to snappymail.

---

<div class="post-metadata">

### Author: ![Lapineige](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/l/bc79bd/32.png) [@Lapineige](https://forum.yunohost.org/u/Lapineige)
#### Post date: [April 23, 2022, 10:13am UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/11 "2022-04-23T10:13:17Z")

</div>

> [@petrus](#):
>
> So, the best option now is to uninstall Rainloop ?

If the information listed above is correct, then it only happens when opening an email. Hence just not using it would not expose to that security flaw.  
Also if you want to uninstall it, one option is to make a backup and keep it until the fix is available.

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [April 23, 2022, 5:36pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/12 "2022-04-23T17:36:00Z")

</div>

In the github issue I shared above, it is said

> I will also remove rainloop which has not seen a commit since May 2021 and seems to have unaddressed security issues

In the rainloop repository, there is a long list of issues without response.  
What’s weird is that the team maintaining it didn’t respond to “Simon Scannell (Vulnerability Researcher)” when contacted.

I already removed it and replaced it with roundcube for now.

---

<div class="post-metadata">

### Author: ![Bram](https://forum.yunohost.org/user_avatar/forum.yunohost.org/bram/32/388_2.png) [@Bram](https://forum.yunohost.org/u/Bram)
#### Post date: [April 24, 2022, 6:17pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/13 "2022-04-24T18:17:44Z")

</div>

Hello,

Sonar has created [a patch](https://blog.sonarsource.com/rainloop-emails-at-risk-due-to-code-flaw) in their post (screenshot bellow) on how to fix this and it would be a great idea to apply it in our app in the mean time to fix this issue.

I’ve tried looking at the app quickly but couldn’t find a way to create this patch easily and I can’t work on it right now so if someone can do it instead it would be great.

 ![image](https://forum.yunohost.org/uploads/default/original/2X/5/5f6990ddbe4817d5ec2cae4bfb6b7ce0b43c7f14.png)

---

<div class="post-metadata">

### Author: ![tituspijean](https://forum.yunohost.org/user_avatar/forum.yunohost.org/tituspijean/32/3584_2.png) [@tituspijean](https://forum.yunohost.org/u/tituspijean)
#### Post date: [April 24, 2022, 7:16pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/14 "2022-04-24T19:16:04Z")

</div>

Nice find! I am trying to work on it.

---

<div class="post-metadata">

### Author: ![nath5394](https://forum.yunohost.org/user_avatar/forum.yunohost.org/nath5394/32/1717_2.png) [@nath5394](https://forum.yunohost.org/u/nath5394)
#### Post date: [April 24, 2022, 8:21pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/15 "2022-04-24T20:21:30Z")

</div>

Super, thank you @tituspijean . I think we would just need to apply the patch with someting like `patch rainloop/v/1.13.0/app/libraries/MailSo/Base/HtmlUtils.php < rainloop_xss.patch` in install&upgrade. And to provide the patch in our package.

---

<div class="post-metadata">

### Author: ![tituspijean](https://forum.yunohost.org/user_avatar/forum.yunohost.org/tituspijean/32/3584_2.png) [@tituspijean](https://forum.yunohost.org/u/tituspijean)
#### Post date: [April 24, 2022, 8:22pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/16 "2022-04-24T20:22:41Z")

</div>

Yup that’s what I’m doing. I only need a bit of time because I’m not used to the `diff` format. 😅

---

<div class="post-metadata">

### Author: ![metyun](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/m/f14d63/32.png) [@metyun](https://forum.yunohost.org/u/metyun)
#### Post date: [April 24, 2022, 8:41pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/17 "2022-04-24T20:41:38Z")

</div>

I tried to apply the patch but I get this error:

```auto
patch: **** malformed patch at line 12: @@ -250,7 +251,7 @@

```

---

<div class="post-metadata">

### Author: ![tituspijean](https://forum.yunohost.org/user_avatar/forum.yunohost.org/tituspijean/32/3584_2.png) [@tituspijean](https://forum.yunohost.org/u/tituspijean)
#### Post date: [April 24, 2022, 9:45pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/18 "2022-04-24T21:45:42Z")

</div>

⚠ Patch in testing: [Fix CVE-2022-29360 by tituspijean · Pull Request #89 · YunoHost-Apps/rainloop\_ynh · GitHub](https://github.com/YunoHost-Apps/rainloop_ynh/pull/89)

---

<div class="post-metadata">

### Author: ![metyun](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/m/f14d63/32.png) [@metyun](https://forum.yunohost.org/u/metyun)
#### Post date: [May 1, 2022, 8:39pm UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/19 "2022-05-01T20:39:12Z")

</div>

J’ai refais le patch avec diff mais pas mieux, j’ai toujours des erreurs.  
Je soupçonne que ce soit lié aux lignes vides, mais vu le peu de chose à changer, j’ai pas creusé plus que ça pourquoi ça échoue. Du coup J’ai modifié manuellement le fichier en attendant de passer sur une application alternative.

---

<div class="post-metadata">

### Author: ![Genesis](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/g/96bed5/32.png) [@Genesis](https://forum.yunohost.org/u/Genesis)
#### Post date: [May 5, 2022, 9:11am UTC](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579/20 "2022-05-05T09:11:15Z")

</div>

Bonjour !

J’ai installé SnappyMail pour ne plus être exposé à cette faille.  
Tout fonctionne très bien, seulement quelqu’un saurait-il me dire dans quel fichier faut-il modifier la variable upload\_max\_filesize pour espérer pouvoir uploader plus de 2 Mo ? 😆

[Next page](https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579.md?page=2)
