Authentication Bypass in Eclipse Mosquitto Affected by Malformed Password File
CVE-2018-12551
8.1HIGH
What is CVE-2018-12551?
Eclipse Mosquitto versions 1.0 through 1.5.5 contain a vulnerability where malformed data in password files may be incorrectly recognized as valid credentials. This can allow attackers to bypass authentication, using malformed usernames (including blank lines) to gain unauthorized access to the service. Users employing the standard 'mosquitto_passwd' utility to manage password files remain unaffected by this issue. This vulnerability poses significant risks to the integrity and confidentiality of data managed by the broker.
Affected Version(s)
Eclipse Mosquitto 1.0
Eclipse Mosquitto <= 1.5.5