Eclipse · Eclipse Mosquitto · CVE-2018-20145
**Name of the Vulnerable Software and Affected Versions**
Eclipse Mosquitto versions 1.5.x through 1.5.4
**Description**
The issue allows for ACL bypass under specific conditions. If the option `per listener settings` was set to true, the default listener was in use, and this listener specified an `acl file`, then the `acl file` was being ignored.
**Recommendations**
For Eclipse Mosquitto versions 1.5.x through 1.5.4, update to version 1.5.5 or later to resolve the issue.