Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option perlistenersettings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.
[
{
"id": "CVE-2018-20145-5abb4622",
"digest": {
"threshold": 0.9,
"line_hashes": [
"237389952011881478287382112648987743294",
"272451151438414953003976969110111933824",
"51697838977234724229644107283187418883",
"282321170269120821608752377155100442388"
]
},
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/eclipse-mosquitto/mosquitto/commit/9097577b49b7fdcf45d30975976dd93808ccc0c4",
"target": {
"file": "src/conf.c"
},
"signature_type": "Line"
},
{
"id": "CVE-2018-20145-700270e5",
"digest": {
"function_hash": "327595239859168560702558468712667619739",
"length": 6844.0
},
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/eclipse-mosquitto/mosquitto/commit/9097577b49b7fdcf45d30975976dd93808ccc0c4",
"target": {
"function": "config__parse_args",
"file": "src/conf.c"
},
"signature_type": "Function"
}
]