Description
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.
Published: 2019-09-11
Score: 7.5 High
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-0656 In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.
Github GHSA Github GHSA GHSA-63qc-p2x4-9fgf Improper Handling of Exceptional Conditions and Origin Validation Error in Eclipse Paho Java client library
History

No history.

Subscriptions

Eclipse Paho Java Client
Redhat Jboss Fuse
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-04T23:03:32.792Z

Reserved: 2019-05-06T00:00:00.000Z

Link: CVE-2019-11777

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-11T18:15:10.757

Modified: 2024-11-21T04:21:46.380

Link: CVE-2019-11777

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-09-11T00:00:00Z

Links: CVE-2019-11777 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses