PT-2019-5497 · Eclipse+2 · Eclipse Mosquitto+2
Yan Jia
·
Published
2019-01-02
·
Updated
2020-08-28
·
CVE-2018-12546
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Mosquitto versions 1.0 through 1.5.5
Description
The issue is related to insufficient access control in the Eclipse Mosquitto message broker. It may allow a remote attacker to gain unauthorized access to protected information. In certain applications, this could result in clients being able to cause effects that would otherwise not be allowed, such as publishing retained messages to topics they no longer have access to.
Recommendations
For Eclipse Mosquitto versions 1.0 through 1.5.5, consider restricting access to topics and implementing proper access control mechanisms to prevent unauthorized message publication. As a temporary workaround, consider disabling the publication of retained messages to sensitive topics until a patch is available.
Exploit
Fix
Incorrect Permission
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Eclipse Mosquitto
Suse