Access Control Bypass in Mosquitto MQTT Broker by Eclipse Foundation
CVE-2017-7650
What is CVE-2017-7650?
In certain versions of the Mosquitto MQTT broker, an issue exists where pattern-based ACLs can be evaded by clients that configure their username or client ID to special characters like '#' or '+'. This flaw can permit unauthorized access to MQTT topics, effectively allowing both local and remote clients to perform operations that they should not be authorized to execute. Moreover, this vulnerability may also be present in third-party authentication and access control plugins utilized with Mosquitto, potentially expanding its impact.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mosquitto 0.15 to 1.4.11 inclusive
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
