In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libmosquitto0", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "libmosquitto0-dev", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "libmosquittopp0", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "libmosquittopp0-dev", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "mosquitto", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "mosquitto-clients", "binary_version": "0.15-2ubuntu1.2" }, { "binary_name": "python-mosquitto", "binary_version": "0.15-2ubuntu1.2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libmosquitto-dev", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "libmosquitto1", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "libmosquittopp-dev", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "libmosquittopp1", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "mosquitto", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "mosquitto-clients", "binary_version": "1.4.8-1ubuntu0.16.04.2" }, { "binary_name": "mosquitto-dev", "binary_version": "1.4.8-1ubuntu0.16.04.2" } ] }