Bug 565671

Summary: Mosquitto Windows Service Unquoted Path vulnerability
Product: Community Reporter: Josh Tanski <JTanski>
Component: Vulnerability ReportsAssignee: Security vulnerabilitied reported against Eclipse projects <vulnerability.reports-inbox>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: P3 CC: JTanski, roger, wayne.beaton
Version: unspecifiedKeywords: security
Target Milestone: ---   
Hardware: PC   
OS: Windows All   
Whiteboard:
Attachments:
Description Flags
Screenshot showing unquoted path to executable none

Description Josh Tanski CLA 2020-07-29 15:35:39 EDT
Created attachment 283738 [details]
Screenshot showing unquoted path to executable

Ran mosquitto-1.6.10a-install-windows-x64.exe  on a fresh Windows Server 2019 install.  Mosquitto Broker service was installed, but path is unquoted and contains space, installer should be fixed to put path in quotes to fix this Windows Service Unquoted Path vulnerability.  Screenshot attached - Path to executable C:\Program Files\mosquitto\mosquitto.exe run should be replaced with something like "C:\Program Files\mosquitto\mosquitto.exe" run
Comment 1 Roger Light CLA 2020-08-11 07:32:10 EDT
Thank you, we've now released an installer which fixes this.