ZeroHour

CVE-2018-12546

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p54
Published
()
Modified
Description

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.

Vendors
eclipse
Products
mosquitto
Weakness
CWE-284, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.