Access Control Bypass in Mosquitto MQTT Broker by Eclipse Foundation
CVE-2017-7650
6.5MEDIUM
What is CVE-2017-7650?
In certain versions of the Mosquitto MQTT broker, an issue exists where pattern-based ACLs can be evaded by clients that configure their username or client ID to special characters like '#' or '+'. This flaw can permit unauthorized access to MQTT topics, effectively allowing both local and remote clients to perform operations that they should not be authorized to execute. Moreover, this vulnerability may also be present in third-party authentication and access control plugins utilized with Mosquitto, potentially expanding its impact.
Affected Version(s)
Mosquitto 0.15 to 1.4.11 inclusive