Medium severity5.5NVD Advisory· Published Jun 25, 2017· Updated May 13, 2026
CVE-2017-9868
CVE-2017-9868
Description
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
Affected products
2- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/eclipse/mosquitto/issues/468nvdIssue TrackingPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00036.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.