Retention Issue in Eclipse Mosquitto Affects Client Access Control
CVE-2018-12546
6.5MEDIUM
What is CVE-2018-12546?
In versions 1.0 through 1.5.5 of Eclipse Mosquitto, a vulnerability exists where a client can publish a retained message to a topic and, even after access to that topic is revoked, the retained messages remain accessible to future clients subscribing to that topic. This behavior can lead to unintended information exposure and could allow clients to perform actions they should not be permitted to, undermining the integrity of access controls within the application.
Affected Version(s)
Eclipse Mosquitto 1.0
Eclipse Mosquitto <= 1.5.5