Description
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Remediation
References
https://github.com/mcollina/aedes/issues/211
https://github.com/mcollina/aedes/issues/212
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json
Related Vulnerabilities
CVE-2022-33987 Vulnerability in npm package got
CVE-2016-10750 Vulnerability in maven package com.hazelcast:hazelcast-client
CVE-2018-25079 Vulnerability in maven package org.webjars.npm:is-url
CVE-2020-26237 Vulnerability in maven package org.webjars.npm:highlight.js
CVE-2021-21322 Vulnerability in npm package fastify-http-proxy