Description
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Remediation
References
https://github.com/mcollina/aedes/issues/211
https://github.com/mcollina/aedes/issues/212
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json
Related Vulnerabilities
CVE-2022-39288 Vulnerability in npm package fastify
CVE-2021-46708 Vulnerability in npm package swagger-ui
CVE-2022-36894 Vulnerability in maven package org.jenkins-ci.plugins:clif-performance-testing
CVE-2023-26136 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2022-48285 Vulnerability in maven package org.webjars.npm:github-com-stuk-jszip