Skip to content

Improper Handling of Exceptional Conditions and Origin Validation Error in Eclipse Paho Java client library

Moderate severity GitHub Reviewed Published Sep 17, 2019 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

maven org.eclipse.paho:org.eclipse.paho.client.mqttv3 (Maven)

Affected versions

< 1.2.1

Patched versions

1.2.1

Description

In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.

References

Published by the National Vulnerability Database Sep 11, 2019
Reviewed Sep 13, 2019
Published to the GitHub Advisory Database Sep 17, 2019
Last updated Feb 1, 2023

Severity

Moderate

CVE ID

CVE-2019-11777

GHSA ID

GHSA-63qc-p2x4-9fgf

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.