Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Carolina Adaros

Researcher fromBosch PSIRT
#39896of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2019-12494
7.5
2019-09-11
Eclipse · Eclipse Paho Java Client Library · CVE-2019-11777
**Name of the Vulnerable Software and Affected Versions** Eclipse Paho Java client library version 1.2.0 **Description** The issue arises when connecting to an MQTT server using TLS and setting a host name verifier in the Eclipse Paho Java client library. The result of the host name verification is not checked, which could allow one MQTT server to impersonate another, providing the client library with incorrect information. **Recommendations** For Eclipse Paho Java client library version 1.2.0, consider updating to a newer version that includes a fix for this issue, as the current version does not properly check the result of the host name verification when connecting to an MQTT server using TLS. At the moment, there is no information about a newer version that contains a fix for this vulnerability.