CVE-2018-12546Improper Access Control in Eclipse Foundation Eclipse Mosquitto

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 51.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 13

Description

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5the_eclipse_foundation/eclipse_mosquitto1.0unspecified+1
Debianeclipse/mosquitto< 1.5.6-1+3
NVDeclipse/mosquitto1.01.5.5

🔴Vulnerability Details

3
GHSA
GHSA-mx88-h56f-w25v: In Eclipse Mosquitto version 12022-05-13
OSV
CVE-2018-12546: In Eclipse Mosquitto version 12019-03-27
CVEList
CVE-2018-12546: In Eclipse Mosquitto version 12019-03-27

📋Vendor Advisories

1
Debian
CVE-2018-12546: mosquitto - In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a ...2018

💬Community

3
Bugzilla
CVE-2018-12546 mosquitto: message privilege escalation [fedora-29]2019-03-29
Bugzilla
CVE-2018-12546 mosquitto: message privilege escalation [epel-7]2019-03-29
Bugzilla
CVE-2018-12546 mosquitto: message privilege escalation2019-03-29
CVE-2018-12546 — Improper Access Control | cvebase