Related Vulnerabilities: CVE-2017-9868  

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

Severity Medium

Remote No

Type Information disclosure

Description

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

AVG-353 mosquitto 1.4.12-1 1.4.14-1 Medium Fixed

16 Jul 2017 ASA-201707-16 AVG-353 mosquitto Medium information disclosure

https://mosquitto.org/2017/06/security-advisory-cve-2017-9868/
https://github.com/eclipse/mosquitto/issues/468
https://github.com/eclipse/mosquitto/commit/09cb1b61c8f48284d9c42bd911faa7525cc689c7