#VU17467 Input validation error in Eclipse Mosquitto - CVE-2018-12551
Published: February 11, 2019
Eclipse Mosquitto
Eclipse
Description
The vulnerability allows a remote attacker to bypass password authentication.
The vulnerability exists due to insufficient validation of malformed input in a password file, when it is used for authentication. Incorrect data in password file will be treated by the application as a username with empty password, allowing attacker to gain unauthorized access to the application.