Improper Authorization in Eclipse Mosquitto - CVE-2021-34434
Published: September 2, 2021
Vulnerability identifier: #VU56273
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34434
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to a subscriptions revoke flaw when using the dynamic security plugin. A remote attacker can send a specially crafted request and obtain subscriptions information.
Affected software
Eclipse Mosquitto
Juniper Cloud Native Router
Debian Linux
Ubuntu
Fedora
mosquitto (Ubuntu package)
mosquitto (Debian package)
mosquitto
Junos cRPD
Juniper Cloud Native Router
Debian Linux
Ubuntu
Fedora
mosquitto (Ubuntu package)
mosquitto (Debian package)
mosquitto
Junos cRPD
How to mitigate CVE-2021-34434
Install updates from vendor's website.
Eclipse Mosquitto - update to 2.0.12
mosquitto (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.11-1ubuntu1.1, 2.0.11-1.2ubuntu0.1
mosquitto (Debian package) - addressed in versions 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1
mosquitto - addressed in versions 2.0.12-1.fc34, 2.0.12-1.fc35
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
mosquitto (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.11-1ubuntu1.1, 2.0.11-1.2ubuntu0.1
mosquitto (Debian package) - addressed in versions 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1
mosquitto - addressed in versions 2.0.12-1.fc34, 2.0.12-1.fc35
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1