Nextcloud GmbH, which develops the open platform Nextcloud designed for creating cloud storage and facilitating team collaboration, has announced the acquisition of the Roundcube email client. Financial details of the deal have not been disclosed, but it is stated that Roundcube will continue to develop as a standalone email client that can be used independently of the Nextcloud platform.
There are no plans for a direct merger of the Roundcube and Nextcloud codebases, nor will the development of the current Nextcloud Mail email client cease; it will continue to be developed. It is noted that both Nextcloud Mail and Roundcube have their strengths and weaknesses, as well as different use cases. Among the immediate plans is the intention to hire additional developers to accelerate the development of Roundcube, creating a comprehensive product suitable for a wide range of users and capable of competing with centralized commercial alternatives.
Roundcube has been in development since 2008 and provides a web-based email client (web interface) that uses the IMAP protocol to access stored emails. server The design of Roundcube is similar to classic email clients and employs Ajax technology for asynchronous data exchange, allowing updates without reloading web page components. proxy server The interface adapts to screen sizes and can be used on both desktop systems and mobile devices. It offers the possibility of customizing the design to individual preferences through a templating system.
The application supports an address book, message search, spell checking, MIME type handling, drag-and-drop navigation, threaded message views, attachment previews, PGP encryption, HTML message display, caching for quick access to email folders, and extensibility through plugins (for example, there is a calendar-scheduling plugin), along with other typical features of standalone email clients. The Roundcube code is written in PHP and is distributed under the GPLv3 license.
Despite the fact that the Nextcloud product is referred to as a 'secure mail client' in the press release, Roundcube's security leaves much to be desired. For instance, in October, malicious actors were found exploiting an unpatched 0-day vulnerability (CVE-2023-5631) in Roundcube, which allowed for JavaScript code execution upon opening a specially crafted message. This could be used, for example, to forward emails to the attackers' server. Similar XSS vulnerabilities in Roundcube are regularly discovered, with fixes issued in September, October, and November. Vulnerabilities have also been found in Roundcube's server components; for example, in 2020, issues arose that allowed PHP code execution on the server or the ability to read local file contents due to unescaped '/..' in plugin names and special characters in shell command executions for image conversion.





Source: opennet.ru
