In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information. Upstream bug: https://github.com/eclipse/mosquitto/issues/468
Created mosquitto tracking bugs for this issue: Affects: epel-7 [bug 1464947] Affects: fedora-all [bug 1464948]