CVE-2017-9868 — Sensitive Information Exposure in Mosquitto
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 70.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateMay 14
Description
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
Also affects: Debian Linux 8.0
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2017-9868: mosquitto - In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world re...↗2017
💬Community
3Bugzilla▶
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information [fedora-all]↗2017-06-26
Bugzilla▶
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information↗2017-06-26
Bugzilla▶
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information [epel-7]↗2017-06-26