Permissions, Privileges, and Access Controls in Eclipse Mosquitto - CVE-2018-12550
Published: February 11, 2019
Vulnerability identifier: #VU17466
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12550
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insecure default permissions to topics and messages, if the ACL file is blank. A remote attacker can gain unauthorized access to sensitive information.
Affected software
Eclipse Mosquitto
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
Opensuse
SUSE Linux
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
Opensuse
SUSE Linux
How to mitigate CVE-2018-12550
Install updates from vendor's website.
Eclipse Mosquitto - update to 1.5.6
mosquitto (Alpine package) - update to 1.4.15-r1
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29
mosquitto (Alpine package) - update to 1.4.15-r1
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Mosquitto
- Debian update for mosquitto
- OpenSUSE Linux update for mosquitto
- OpenSUSE Linux update for mosquitto
- Permissions, Privileges, and Access Controls in mosquitto (Alpine package)
- Fedora 28 update for mosquitto
- Fedora 29 update for mosquitto
- Fedora EPEL 7 update for mosquitto