CyberRota Analysis
AI-GeneratedThe vulnerability affects the Moquette Java MQTT broker, where the PostOffice.publishWill function improperly handles authorization checks, allowing clients to publish Last-Will messages to restricted topics without permission. This can lead to unauthorized message injection, potentially compromising the integrity of the messaging system. Organizations using affected versions of Moquette should prioritize upgrading to version 0.18.1 to mitigate the risk of unauthorized access and message manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in version 0.18.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)