PT-2021-6512 · Eclipse+2 · Eclipse Mosquitto+2
Syncxxx Song
·
Published
2021-08-30
·
Updated
2023-11-21
·
CVE-2021-34434
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Mosquitto versions 2.0 through 2.0.11
Description
The issue is related to the dynamic security plugin in Eclipse Mosquitto. When the ability for a client to make subscriptions on a topic is revoked while a durable client is offline, existing subscriptions for that client are not revoked. This is due to an authorization flaw. The exploitation of this flaw allows a remote attacker to access confidential data.
Recommendations
For Eclipse Mosquitto versions 2.0 through 2.0.11, as a temporary workaround, consider disabling the dynamic security plugin until a patch is available. Restrict access to the subscription functionality for durable clients to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Mosquitto
Linuxmint
Ubuntu