2.1
CVSSv2

CVE-2017-9868

Published: 25/06/2017 Updated: 12/03/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Mosquitto up to and including 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse mosquitto

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #865959 mosquitto: CVE-2017-9868: mosquittodb can be read by all Package: src:mosquitto; Maintainer for src:mosquitto is Roger A Light <roger@atchooorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 26 Jun 2017 05:39:02 UTC Severity: important Tags: fixed-upstream, secu ...
In Mosquitto through 1412, mosquittodb (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information ...