CVE-2018-3778

Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
References
Link Resource
https://github.com/mcollina/aedes/issues/211 Issue Tracking Patch Third Party Advisory
https://github.com/mcollina/aedes/issues/212 Issue Tracking Third Party Advisory
https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:aedes_project:aedes:*:*:*:*:*:*:*:*

History

28 Feb 2023, 17:55

Type Values Removed Values Added
References (MISC) https://github.com/mcollina/aedes/issues/212 - Third Party Advisory (MISC) https://github.com/mcollina/aedes/issues/212 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/mcollina/aedes/issues/211 - Patch, Third Party Advisory (MISC) https://github.com/mcollina/aedes/issues/211 - Issue Tracking, Patch, Third Party Advisory

Information

Published : 2018-08-08 20:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-3778

Mitre link : CVE-2018-3778

CVE.ORG link : CVE-2018-3778


JSON object : View

Products Affected

aedes_project

  • aedes
CWE
CWE-863

Incorrect Authorization

CWE-285

Improper Authorization