PT-2019-5496 · Eclipse+2 · Eclipse Mosquitto+2

Charles Taylor

·

Publicado

2019-01-14

·

Atualizado

2019-10-26

·

CVE-2018-12551

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eclipse Mosquitto versions 1.0 through 1.5.5
Description The issue is related to the authentication procedure in Eclipse Mosquitto. When configured to use a password file for authentication, any malformed data in the file is treated as valid, potentially allowing clients to bypass authentication. Specifically, a blank line in the password file can be treated as a valid empty username, enabling unauthorized access to the broker. This issue does not affect other security measures, and users who have only used the mosquitto passwd utility to manage their password files are not affected.
Recommendations For Eclipse Mosquitto versions 1.0 through 1.5.5, ensure that password files are properly formatted and do not contain malformed data to prevent unauthorized access. As a temporary workaround, consider manually reviewing and correcting the password file to prevent exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1213
BDU:2020-03294
CVE-2018-12551
DLA-1972-1
DSA-4388-1
DSA-4388-2
OPENSUSE-SU-2019:0233-1
OPENSUSE-SU-2019:0237-1
OPENSUSE-SU-2019_0233-1
OPENSUSE-SU-2024:11057-1

Produtos afetados

Alt Linux
Eclipse Mosquitto
Suse