First published: Thu Dec 13 2018(Updated: )
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Mosquitto | >=1.5<1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identified as CVE-2018-20145 is an ACL bypass issue in Eclipse Mosquitto 1.5.x before 1.5.5.
CVE-2018-20145 allows ACL bypass if the option per_listener_settings is set to true and the default listener specifies an acl_file.
The severity of CVE-2018-20145 is rated as high with a CVSS score of 7.5.
To fix CVE-2018-20145, update Eclipse Mosquitto to version 1.5.5 or later.
More information about CVE-2018-20145 can be found in the following references: [link1], [link2], [link3].