PT-2019-5497 · Eclipse+2 · Eclipse Mosquitto+2

Yan Jia

·

Published

2019-01-02

·

Updated

2020-08-28

·

CVE-2018-12546

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Mosquitto versions 1.0 through 1.5.5
Description The issue is related to insufficient access control in the Eclipse Mosquitto message broker. It may allow a remote attacker to gain unauthorized access to protected information. In certain applications, this could result in clients being able to cause effects that would otherwise not be allowed, such as publishing retained messages to topics they no longer have access to.
Recommendations For Eclipse Mosquitto versions 1.0 through 1.5.5, consider restricting access to topics and implementing proper access control mechanisms to prevent unauthorized message publication. As a temporary workaround, consider disabling the publication of retained messages to sensitive topics until a patch is available.

Exploit

Fix

Incorrect Permission

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1213
BDU:2020-03296
CVE-2018-12546
DSA-4388-1
DSA-4388-2
OPENSUSE-SU-2019:0233-1
OPENSUSE-SU-2019:0237-1
OPENSUSE-SU-2019_0233-1
OPENSUSE-SU-2024:11057-1

Affected Products

Alt Linux
Eclipse Mosquitto
Suse