Vulnerability Description
MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.
CVSS Score
6.5
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mqtt.Js Project | Mqtt.Js | >= 2.0.0, < 2.15.0 |
Related Weaknesses (CWE)
References
- https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e992PatchThird Party Advisory
- https://github.com/mqttjs/MQTT.js/releases/tag/v2.15.0Release NotesThird Party Advisory
- https://jvn.jp/en/jp/JVN45494523/index.htmlThird Party AdvisoryVDB Entry
- https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e992PatchThird Party Advisory
- https://github.com/mqttjs/MQTT.js/releases/tag/v2.15.0Release NotesThird Party Advisory
- https://jvn.jp/en/jp/JVN45494523/index.htmlThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-10910?
CVE-2017-10910 is a vulnerability with a CVSS score of 6.5 (MEDIUM). MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.
How severe is CVE-2017-10910?
CVE-2017-10910 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10910?
Check the references section above for vendor advisories and patch information. Affected products include: Mqtt.Js Project Mqtt.Js.