CVE-2021-34434: Medium severity tibco messaging - eclipse mosquitto distribution - core vulnerability
Published Aug 30, 2021
·Updated
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
Affected Software
4 affected componentsFixes available
debian/mosquitto<=2.0.11-1, <=2.0.11-1.2
1.5.7-1+deb10u12.0.11-1+deb11u12.0.11-1.2+deb12u12.0.18-1
Eclipse Mosquitto>=2.0.0<=2.0.11
fedoraproject fedora=34
fedoraproject fedora=35
Event History
Aug 30, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Aug 31, 2021
Data Sourced
07:33 PM
SeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-34434?
CVE-2021-34434 is a vulnerability in Eclipse Mosquitto versions 2.0 to 2.0.11.
2
What is the severity of CVE-2021-34434?
The severity of CVE-2021-34434 is high with a severity value of 5.3.
3
How does CVE-2021-34434 affect Eclipse Mosquitto?
CVE-2021-34434 affects Eclipse Mosquitto versions 2.0 to 2.0.11.
4
Is Fedora affected by CVE-2021-34434?
Yes, Fedora versions 34 and 35 are affected by CVE-2021-34434.
5
How can I fix CVE-2021-34434?
To fix CVE-2021-34434, you should update to version 2.0.18 of the Mosquitto package.