VYPR
High severity7.5OSV Advisory· Published Dec 13, 2018· Updated Jun 17, 2026

CVE-2018-20145

CVE-2018-20145

Description

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Eclipse/MosquittoOSV2 versions
    v1.4.1, v1.4.10, v1.4.11, …+ 1 more
    • (no CPE)range: v1.4.1, v1.4.10, v1.4.11, …
    • cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*range: >=1.5,<1.5.5
  • Range: <1.5.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.