
Cloud Vulnerability DB
A community-led vulnerabilities database
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability was discovered by researchers from the School of Cyber Science and Technology, Shandong University and was assigned CVE-2023-33657 (NVD, GitHub Issue).
The vulnerability is caused by improper data tracing when handling publish messages. When sending a large number of malformed data packets to the server, it may trigger a heap-use-after-free condition. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 HIGH with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
An attacker could exploit this vulnerability to cause a denial of service attack by crashing the NanoMQ broker. The vulnerability affects the availability of the system while not impacting confidentiality or integrity (NVD).
The vulnerability requires sending malformed packets multiple times (2-15 times) to trigger the crash. It can be exploited remotely without requiring authentication. A proof of concept (PoC) was developed by the researchers to demonstrate the vulnerability (GitHub Issue).
The vulnerability has been fixed in a patch that addresses the data racing issue by cloning retain messages. The fix was merged through pull request #1187 on April 20, 2023 (GitHub PR).
According to the developer who fixed the issue, this was described as a rarely triggered issue that is hardly seen in real business scenarios (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."