CyberRota Analysis
AI-GeneratedMoquette MQTT broker versions prior to 0.18.1 are vulnerable due to a flaw in the PostOffice.publishWill function, which allows remote clients to publish unauthorized messages to ACL-protected topics when anonymous access is enabled. This can lead to the injection of attacker-controlled messages, potentially compromising the integrity of the messaging system. Organizations using Moquette in environments where anonymous access is permitted should prioritize upgrading to version 0.18.1 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform an abnormal client disconnect, causing the broker to inject attacker-controlled messages into a topic for which the client lacks write permission. This issue is fixed in version 0.18.1.