SB2019021001 - Permissions, Privileges, and Access Controls in mosquitto (Alpine package)
Published: February 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2018-12546)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote authenticated user to gain access to potentially sensitive information.
The vulnerability exists due to an error when messages were still delivered to clients after their access to topic was revoked. A remote authenticated user was able to obtain potentially sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=68e4e4a13ae7d52d37708f6d7393a5a6ef0ef856
- https://git.alpinelinux.org/aports/commit/?id=1a43a53ec67e2c5ca5fa770026cd904d745f32a1
- https://git.alpinelinux.org/aports/commit/?id=54e5c2f7374a2dba0bc5dbc825e3cb9557de2d1b
- https://git.alpinelinux.org/aports/commit/?id=cdf3e55bbad03e4036a926c6ec33aae93e695537
- https://git.alpinelinux.org/aports/commit/?id=0615c8c70a2ec6b20460291a2755e9e36f393205
- https://git.alpinelinux.org/aports/commit/?id=c000685cbe12c9f51e9d651aff660e8b3ebc8f70