CVE-2018-20145
13.12.2018, 20:29
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.Enginsight
Vendor | Product | Version |
---|---|---|
eclipse | mosquitto | 1.5 ≤ 𝑥 < 1.5.5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References