CVE-2017-9868: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Eclipse Mosquitto: up to and including 1.4.12

Published 2017-06-25. Last modified 2026-06-17.