VulnerabilityModified
CVE-2017-9868
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
MEDIUM 5.5EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- eclipse/mosquitto · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/eclipse/mosquitto/issues/468Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00036.htmlMailing List, Third Party Advisory
- https://github.com/eclipse/mosquitto/issues/468Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00036.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.