Related Vulnerabilities: CVE-2021-34434  

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

AVG-2332 mosquitto 2.0.11-1 Medium Vulnerable

https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324