Eclipse Foundation Vulnerabilities and Affected Products
Vulnerabilities associated with Mosquitto.
Products
Clear product- Eclipse Glassfish12 vulnerabilities
- ThreadX12 vulnerabilities
- NetX Duo11 vulnerabilities
- Eclipse Theia10 vulnerabilities
- Eclipse Jetty9 vulnerabilities
- Eclipse Milo6 vulnerabilities
- Jetty6 vulnerabilities
- Eclipse OMR4 vulnerabilities
- Eclipse Vert.x4 vulnerabilities
- Mosquitto4 vulnerabilities
- OpenJ94 vulnerabilities
- USBX4 vulnerabilities
- Eclipse CSI - PIA3 vulnerabilities
- Eclipse BaSyx2 vulnerabilities
- Eclipse KUKSA - Databroker2 vulnerabilities
- Eclipse Open VSX2 vulnerabilities
- Eclipse OpenJ92 vulnerabilities
- Eclipse OpenMQ2 vulnerabilities
- Eclipse ThreadX - NetX Duo2 vulnerabilities
- Glassfish2 vulnerabilities
- NextX Duo2 vulnerabilities
- Open J92 vulnerabilities
- Parsson2 vulnerabilities
- Vert.x2 vulnerabilities
- BlueChi1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3935MEDIUM | Eclipse Mosquito: Double free vulnerabilityIn Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker. CWE-415Oct 30, 2024 | CVSS6.0v4.0 | EPSS0.749% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10525HIGH | Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callbackIn Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients. | CVSS7.2v4.0 | EPSS58.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8376HIGH | Memory leakIn Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets. | CVSS7.2v4.0 | EPSS0.743% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7650MEDIUM | In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party authentication/access control plugins for Mosquitto. CWE-287Sep 11, 2017 | CVSS6.5v3.0 | EPSS2.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |