Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json | third party advisory |
https://github.com/mcollina/aedes/issues/212 | issue tracking third party advisory |
https://github.com/mcollina/aedes/issues/211 | issue tracking third party advisory patch |