Headline
CVE-2018-3778: security-wg/457.json at main · nodejs/security-wg
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Permalink
Cannot retrieve contributors at this time
{
"id": 457,
"title": "Improper Authorization",
"overview": "Aedes does not respect its own authorization rules when a client sets a Last Will",
"created_at": "2018-08-07",
"updated_at": "2018-08-07",
"publish_date": "2018-08-07",
"author": {
"name": "Matteo Collina",
"website": null,
"username": “mcollina”
},
"module_name": "aedes",
"cves": [
“CVE-2018-3778”
],
"vulnerable_versions": "<=0.35.0",
"patched_versions": ">=0.35.1",
"recommendation": "Update aedes module to version >= 0.35.1",
"references": [
"https://github.com/mcollina/aedes/issues/211",
“https://github.com/mcollina/aedes/issues/212”
],
"cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
"cvss_score": 5.0,
"coordinating_vendor": null
}