CVE-2019-11777

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-11777
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11777.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-11777
Aliases
Published
2019-09-11T18:15:10Z
Modified
2024-09-03T02:23:17.989682Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.

References

Affected packages

Git / github.com/eclipse/paho.mqtt.java

Affected ranges

Type
GIT
Repo
https://github.com/eclipse/paho.mqtt.java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

help

v0.*

v0.1
v0.2
v0.2.1
v0.4.0
v0.9.0

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.2.0