When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: eclipse
Published: 2019-03-27T17:26:20
Updated: 2024-08-05T08:38:06.290Z
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12550
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2019-03-27T18:29:00.303
Modified: 2024-11-21T03:45:25.397
Link: CVE-2018-12550
 Redhat
                        Redhat
                    No data.