Authentication Bypass in Eclipse Mosquitto Affected by Malformed Password File
CVE-2018-12551
What is CVE-2018-12551?
Eclipse Mosquitto versions 1.0 through 1.5.5 contain a vulnerability where malformed data in password files may be incorrectly recognized as valid credentials. This can allow attackers to bypass authentication, using malformed usernames (including blank lines) to gain unauthorized access to the service. Users employing the standard 'mosquitto_passwd' utility to manage password files remain unaffected by this issue. This vulnerability poses significant risks to the integrity and confidentiality of data managed by the broker.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Eclipse Mosquitto 1.0
Eclipse Mosquitto <= 1.5.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
