CVE-2017-9868 log

Source
Severity Medium
Remote No
Type Information disclosure
Description
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
Group Package Affected Fixed Severity Status Ticket
AVG-353 mosquitto 1.4.12-1 1.4.14-1 Medium Fixed
Date Advisory Group Package Severity Type
16 Jul 2017 ASA-201707-16 AVG-353 mosquitto Medium information disclosure
References
https://mosquitto.org/2017/06/security-advisory-cve-2017-9868/
https://github.com/eclipse/mosquitto/issues/468
https://github.com/eclipse/mosquitto/commit/09cb1b61c8f48284d9c42bd911faa7525cc689c7