CVE-2018-20145: High severity tibco messaging - eclipse mosquitto distribution - core vulnerability
Published Dec 13, 2018
·Updated
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option perlistenersettings was set to true, and the default listener was in use, and the default listener specified an aclfile, then the acl file was being ignored.
Affected Software
1 affected component
Eclipse Mosquitto>=1.5<1.5.5
Remediation
Patch Available
Event History
Dec 13, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability identified as CVE-2018-20145?
The vulnerability identified as CVE-2018-20145 is an ACL bypass issue in Eclipse Mosquitto 1.5.x before 1.5.5.
2
How does CVE-2018-20145 affect Eclipse Mosquitto?
CVE-2018-20145 allows ACL bypass if the option per_listener_settings is set to true and the default listener specifies an acl_file.
3
What is the severity of CVE-2018-20145?
The severity of CVE-2018-20145 is rated as high with a CVSS score of 7.5.
4
How can I fix CVE-2018-20145 in Eclipse Mosquitto?
To fix CVE-2018-20145, update Eclipse Mosquitto to version 1.5.5 or later.
5
Where can I find more information about CVE-2018-20145?
More information about CVE-2018-20145 can be found in the following references: [link1], [link2], [link3].