Dynamic Security Plugin Vulnerability in Eclipse Mosquitto
CVE-2021-34434
5.3MEDIUM
Key Information:
- Vendor
The Eclipse Foundation
- Status
- Vendor
- CVE Published:
- 30 August 2021
What is CVE-2021-34434?
In versions 2.0 to 2.0.11 of Eclipse Mosquitto, a flaw exists in the dynamic security plugin. When a client's ability to subscribe to a topic is revoked while the client is offline, any existing subscriptions for that client are not correctly retracted. This oversight may lead to unauthorized access or message delivery to unintended clients, posing a risk to the integrity of the messaging system.
Affected Version(s)
Eclipse Mosquitto 2.0
Eclipse Mosquitto <= 2.0.11
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved