Audit Open Original ↗
Eclipse Mosquitto
Type
Security review
Client
OSTIF
Date
2023-03
Domain
AppSec
Effort
—
Section
—
Trail of Bits's security review of OSTIF (Mar 2023) identified 8 issues: 5 high, 2 medium, and 1 low.
Findings · 8
- 1 Insu cient default configuration file permissions High
- 2 Unclear ACL, role, group enforcement priority Medium
- 3 Missing global connection rate limiting High
- 4 Plaintext password storage and handling High
- 5 Bridge -> broker -> bridge message looping High
- 6 Broker does not check configuration filesystem permissions Medium
- 7 Configuration reload may cause inconsistent behavior Low
- 8 Clients can publish last will messages to $CONTROL topics High
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related