PT-2018-3529 · Eclipse+2 · Eclipse Mosquitto+2

Yan Jia

·

Published

2018-12-03

·

Updated

2019-10-26

·

CVE-2018-12550

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Eclipse Mosquitto versions 1.0 through 1.5.5
Description: The issue is related to the configuration of the access control list (ACL) file in Eclipse Mosquitto. When the ACL file is empty or contains only comments or blank lines, Mosquitto previously used a default allow policy. However, the new behavior is to deny all access if the ACL file is empty. This change in behavior may lead to unexpected configuration issues. The vulnerability is also related to insufficient input validation and incorrect implementation of functions, which may allow a remote attacker to gain unauthorized access to protected information.
Recommendations: For Eclipse Mosquitto versions 1.0 through 1.5.5, ensure that the ACL file is properly configured and not empty to avoid denying all access. As a temporary workaround, consider defining a default ACL policy to minimize the risk of exploitation. Restrict access to the broker until a proper ACL configuration is in place.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1213
BDU:2020-03295
CVE-2018-12550
DLA-1972-1
DSA-4388-1
DSA-4388-2
OPENSUSE-SU-2019:0233-1
OPENSUSE-SU-2019:0237-1
OPENSUSE-SU-2019_0233-1
OPENSUSE-SU-2024:11057-1

Affected Products

Alt Linux
Eclipse Mosquitto
Suse