First published: Mon Aug 30 2021(Updated: )
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
Credit: emo@eclipse.org emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Mosquitto | >=2.0.0<=2.0.11 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
debian/mosquitto | <=2.0.11-1<=2.0.11-1.2 | 1.5.7-1+deb10u1 2.0.11-1+deb11u1 2.0.11-1.2+deb12u1 2.0.18-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34434 is a vulnerability in Eclipse Mosquitto versions 2.0 to 2.0.11.
The severity of CVE-2021-34434 is high with a severity value of 5.3.
CVE-2021-34434 affects Eclipse Mosquitto versions 2.0 to 2.0.11.
Yes, Fedora versions 34 and 35 are affected by CVE-2021-34434.
To fix CVE-2021-34434, you should update to version 2.0.18 of the Mosquitto package.