PT-2018-3529 · Eclipse+2 · Eclipse Mosquitto+2
Yan Jia
·
Publicado
2018-12-03
·
Atualizado
2019-10-26
·
CVE-2018-12550
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Eclipse Mosquitto versions 1.0 through 1.5.5
Description:
The issue is related to the configuration of the access control list (ACL) file in Eclipse Mosquitto. When the ACL file is empty or contains only comments or blank lines, Mosquitto previously used a default allow policy. However, the new behavior is to deny all access if the ACL file is empty. This change in behavior may lead to unexpected configuration issues. The vulnerability is also related to insufficient input validation and incorrect implementation of functions, which may allow a remote attacker to gain unauthorized access to protected information.
Recommendations:
For Eclipse Mosquitto versions 1.0 through 1.5.5, ensure that the ACL file is properly configured and not empty to avoid denying all access. As a temporary workaround, consider defining a default ACL policy to minimize the risk of exploitation. Restrict access to the broker until a proper ACL configuration is in place.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Eclipse Mosquitto
Suse