CVE-2017-9868

MEDIUM

Mosquitto <1.4.12 - Info Disclosure

Title source: llm

Description

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
eclipse/mosquitto < 1.4.12
debian/debian_linux
n/a/n/a
Published Jun 25, 2017
Tracked Since Feb 18, 2026