CVE-2018-12546

Description

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.252

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2018-12546,CVE-2018-12550,CVE-2018-12551 are affected in Mosquitto 1.5.5Windows
mosquitto security update(DSA-4388-1) mosquitto_1.4.10-3+deb9u3_i386.debLinux
mosquitto security update(DSA-4388-1) mosquitto_1.4.10-3+deb9u3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234