CVE-2018-3778
08.08.2018, 20:29
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.Enginsight
Vendor | Product | Version |
---|---|---|
aedes_project | aedes | 𝑥 < 0.35.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References