An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/nanomq/nanomq | product |
https://github.com/nanomq/nanomq/issues/1782#issuecomment-2171025812 | exploit issue tracking patch |
https://github.com/songxpu/bug_report/blob/master/MQTT/NanoMQ/CVE-2024-42655.md | exploit third party advisory |