Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6fp-h8pq-3x5p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

EPSS

Процентиль: 44%
0.00213
Низкий

7.5 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

CVSS3: 7.5
nvd
около 7 лет назад

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

CVSS3: 7.5
debian
около 7 лет назад

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option ...

EPSS

Процентиль: 44%
0.00213
Низкий

7.5 High

CVSS3

Дефекты

CWE-732