Description
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Remediation
References
https://github.com/mcollina/aedes/issues/211
https://github.com/mcollina/aedes/issues/212
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json
Related Vulnerabilities
CVE-2014-3656 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2017-5651 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2021-36774 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2020-28480 Vulnerability in npm package jointjs
CVE-2021-46364 Vulnerability in maven package info.magnolia:magnolia-core