Bug 1190048 - (CVE-2021-34434) VUL-1: CVE-2021-34434: mosquitto: Existing subscriptions for that client are not revoked
(CVE-2021-34434)
VUL-1: CVE-2021-34434: mosquitto: Existing subscriptions for that client are ...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Martin Hauke
Security Team bot
https://smash.suse.de/issue/308605/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-01 08:54 UTC by Robert Frohl
Modified: 2021-09-01 09:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-09-01 08:54:57 UTC
rh#1999865

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1999865
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-34434
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34434
https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324
Comment 1 Robert Frohl 2021-09-01 08:56:38 UTC
seems to be still an issue for Factory, Leap and Backports