CVE-2017-9868Sensitive Information Exposure in Mosquitto

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 70.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 14

Description

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianeclipse/mosquitto< 1.4.14-1+3
NVDeclipse/mosquitto1.4.12

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m438-p9g2-x57w: In Mosquitto through 12022-05-14
OSV
CVE-2017-9868: In Mosquitto through 12017-06-25
CVEList
CVE-2017-9868: In Mosquitto through 12017-06-25

📋Vendor Advisories

1
Debian
CVE-2017-9868: mosquitto - In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world re...2017

💬Community

3
Bugzilla
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information [fedora-all]2017-06-26
Bugzilla
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information2017-06-26
Bugzilla
CVE-2017-9868 mosquitto: World-readable persistence file possibly leaking sensitive information [epel-7]2017-06-26
CVE-2017-9868 — Sensitive Information Exposure | cvebase