Description
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Remediation
References
https://github.com/mcollina/aedes/issues/211
https://github.com/mcollina/aedes/issues/212
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json
Related Vulnerabilities
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2021-21179 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-28196 Vulnerability in npm package krb5
CVE-2023-29515 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common