Dynamic Security Plugin Vulnerability in Eclipse Mosquitto
CVE-2021-34434
5.3MEDIUM
Key Information:
- Vendor
The Eclipse Foundation
- Status
- Vendor
- CVE Published:
- 30 August 2021
What is CVE-2021-34434?
In versions 2.0 to 2.0.11 of Eclipse Mosquitto, a flaw exists in the dynamic security plugin. When a client's ability to subscribe to a topic is revoked while the client is offline, any existing subscriptions for that client are not correctly retracted. This oversight may lead to unauthorized access or message delivery to unintended clients, posing a risk to the integrity of the messaging system.
Affected Version(s)
Eclipse Mosquitto 2.0
Eclipse Mosquitto <= 2.0.11