Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option perlistenersettings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.
[
    {
        "id": "CVE-2018-20145-5abb4622",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "237389952011881478287382112648987743294",
                "272451151438414953003976969110111933824",
                "51697838977234724229644107283187418883",
                "282321170269120821608752377155100442388"
            ]
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/eclipse-mosquitto/mosquitto/commit/9097577b49b7fdcf45d30975976dd93808ccc0c4",
        "target": {
            "file": "src/conf.c"
        },
        "signature_type": "Line"
    },
    {
        "id": "CVE-2018-20145-700270e5",
        "digest": {
            "function_hash": "327595239859168560702558468712667619739",
            "length": 6844.0
        },
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/eclipse-mosquitto/mosquitto/commit/9097577b49b7fdcf45d30975976dd93808ccc0c4",
        "target": {
            "function": "config__parse_args",
            "file": "src/conf.c"
        },
        "signature_type": "Function"
    }
]