When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1972-1 | mosquitto security update |
![]() |
DSA-4388-1 | mosquitto security update |
![]() |
EUVD-2018-4510 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.290Z
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12550

No data.

Status : Modified
Published: 2019-03-27T18:29:00.303
Modified: 2024-11-21T03:45:25.397
Link: CVE-2018-12550

No data.

No data.