Description
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Remediation
References
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json
https://github.com/mcollina/aedes/issues/212
https://github.com/mcollina/aedes/issues/211
Related Vulnerabilities
CVE-2022-23181 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-8910 Vulnerability in npm package google-closure-library
CVE-2016-10624 Vulnerability in npm package selenium-chromedriver
CVE-2019-15954 Vulnerability in npm package total.js
CVE-2011-4838 Vulnerability in maven package org.jruby:jruby