Bugzilla – Bug 1190048
VUL-1: CVE-2021-34434: mosquitto: Existing subscriptions for that client are not revoked
Last modified: 2021-09-01 09:15:10 UTC
rh#1999865 In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked. https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324 References: https://bugzilla.redhat.com/show_bug.cgi?id=1999865 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-34434 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34434 https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324
seems to be still an issue for Factory, Leap and Backports