Vulnerability Report: GO-2021-0083
- CVE-2019-12496, GHSA-vfxc-r2gx-v2vq
- Affects: github.com/hybridgroup/gobot
- Published: Apr 14, 2021
- Modified: May 20, 2024
TLS certificate verification is skipped when connecting to a MQTT server. This allows an attacker who can MITM the connection to read, or forge, messages passed between the client and server.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.12.1-0.20190521122906-c1aa4f867846
Aliases
References
- https://github.com/hybridgroup/gobot/commit/c1aa4f867846da4669ecf3bc3318bd96b7ee6f3f
- https://github.com/hybridgroup/gobot/releases/tag/v1.13.0
- https://vuln.go.dev/ID/GO-2021-0083.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.