CVE-2018-12550

Description

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.47

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2018-12546,CVE-2018-12550,CVE-2018-12551 are affected in Mosquitto 1.5.5Windows
mosquitto security update(DSA-4388-1) mosquitto_1.4.10-3+deb9u3_i386.debLinux
mosquitto security update(DSA-4388-1) mosquitto_1.4.10-3+deb9u3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234