Bug 1694021 (CVE-2018-12546)

Summary: CVE-2018-12546 mosquitto: message privilege escalation
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: linville, mail, richmattes
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-05-09 16:08:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1694022, 1694023    
Bug Blocks:    

Description Dhananjay Arunesh 2019-03-29 10:23:19 UTC
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.

Reference:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=543127

Comment 1 Dhananjay Arunesh 2019-03-29 10:24:10 UTC
Created mosquitto tracking bugs for this issue:

Affects: fedora-29 [bug 1694022]

Comment 2 Dhananjay Arunesh 2019-03-29 10:24:28 UTC
Created mosquitto tracking bugs for this issue:

Affects: epel-7 [bug 1694023]