CVE-2018-20145

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2018
Last modified:
24/08/2020

Description

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* 1.5 (including) 1.5.5 (excluding)