Permissions, Privileges, and Access Controls in Eclipse Mosquitto - CVE-2018-12546
Published: February 11, 2019
Vulnerability identifier: #VU17464
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12546
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to potentially sensitive information.
The vulnerability exists due to an error when messages were still delivered to clients after their access to topic was revoked. A remote authenticated user was able to obtain potentially sensitive information.
Affected software
Eclipse Mosquitto
mosquitto (Debian package)
mosquitto (Alpine package)
mosquitto
Fedora
SUSE Linux
Opensuse
mosquitto (Debian package)
mosquitto (Alpine package)
mosquitto
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2018-12546
Install updates from vendor's website.
Eclipse Mosquitto - update to 1.5.6
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto (Alpine package) - addressed in versions 1.4.15-r1, 1.4.15-r5
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto (Alpine package) - addressed in versions 1.4.15-r1, 1.4.15-r5
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Mosquitto
- Debian update for mosquitto
- OpenSUSE Linux update for mosquitto
- OpenSUSE Linux update for mosquitto
- Permissions, Privileges, and Access Controls in mosquitto (Alpine package)
- Fedora 28 update for mosquitto
- Fedora 29 update for mosquitto
- Fedora EPEL 7 update for mosquitto