MEDIUM5.3
GHSA-4cmx-hrq9-c23p
Improper Authorization in aedes
Quick fix
GHSA-4cmx-hrq9-c23p — aedes: upgrade to the fixed version with the command below.
npm install aedes@0.35.1Details
Versions of `aedes` before 0.35.1 does not respect its own authorization rules when a client sets a `Last Will`.
## Recommendation
Update to version 0.35.1 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3778[ADVISORY]
- https://github.com/moscajs/aedes/issues/211[WEB]
- https://github.com/moscajs/aedes/issues/212[WEB]
- https://github.com/moscajs/aedes/commit/ffbc1702bb24b596afbb96407cc6db234a4044a8[WEB]
- https://github.com/moscajs/aedes[PACKAGE]
- https://github.com/nodejs/security-wg/blob/master/vuln/npm/457.json[WEB]