First published: Sun Jun 25 2017(Updated: )
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Messaging - Eclipse Mosquitto Distribution - Core | <=1.4.12 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9868 has a medium severity level as it allows local users to access sensitive data.
To fix CVE-2017-9868, ensure that the mosquitto.db file has the proper permissions to restrict access.
CVE-2017-9868 affects Eclipse Mosquitto versions up to 1.4.12 and Debian GNU/Linux 8.0.
CVE-2017-9868 can expose sensitive MQTT topic information stored in the mosquitto.db persistence file.
Local users on systems running vulnerable versions of Eclipse Mosquitto and Debian GNU/Linux are primarily impacted by CVE-2017-9868.