Show plain JSON{"id": "CVE-2018-12550", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.2}]}, "published": "2019-03-27T18:29:00.303", "references": [{"url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=541870", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "emo@eclipse.org"}, {"url": "https://lists.debian.org/debian-lts-announce/2019/10/msg00035.html", "source": "emo@eclipse.org"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}, {"type": "Secondary", "source": "emo@eclipse.org", "description": [{"lang": "en", "value": "CWE-440"}]}], "descriptions": [{"lang": "en", "value": "When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that all access is denied, which is not a useful configuration but is not unexpected."}, {"lang": "es", "value": "Cuando Eclipse Mosquitto, desde la versi\u00f3n 1.0 hasta la 1.5.5 (incluidas), est\u00e1 configurado para emplear un archivo de listas de control de acceso (ACL) y ese archivo est\u00e1 vac\u00edo o solo contiene comentarios o l\u00edneas en blanco, Mosquitto considerar\u00e1 que no se ha definido ning\u00fan archivo ACL y emplear\u00e1 una pol\u00edtica de permisividad por defecto. El nuevo comportamiento es que un archivo ACL vac\u00edo significa que todos los accesos se deniegan, lo que no es una configuraci\u00f3n \u00fatil, pero no se espera."}], "lastModified": "2019-10-09T23:34:04.010", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "734742C3-741C-461E-9739-B13C25C5420D", "versionEndIncluding": "1.5.5", "versionStartIncluding": "1.0"}], "operator": "OR"}]}], "sourceIdentifier": "emo@eclipse.org"}