CVE-2018-12546

MEDIUM6.5EPSS 0.18%

mosquitto - security update

發布日:2019/3/27修改日:2025/12/3
也稱為:ALPINE-CVE-2018-12546DEBIAN-CVE-2018-12546

描述

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

參考連結(2)