Junglewise Threat Intelligence

CVE-2018-3778: aedes improper authorization in last will messages

CVE-2018-3778 · Severity: low · CVSS 3.1 · Published 2018-08-15

Technologies: aedes (npm). Vendors: npm.

Executive brief

aedes is an open-source MQTT broker used in IoT and messaging applications to route messages between connected devices. A flaw in versions before 0.35.1 causes the broker to ignore its own authorization policies when processing Last Will messages—a feature that auto-publishes a message if a client disconnects unexpectedly. An attacker can exploit this to bypass restrictions and send messages to topics they should not have access to, potentially exposing sensitive data or disrupting message integrity in connected systems.

Technical details

The vulnerability is an improper authorization (CWE-285, CWE-863) in aedes's Last Will and Testament (LWT) handling. aedes allows administrators to define an authorizePublish callback to restrict which clients can publish to which topics, but this authorization check is not applied when the broker publishes a Last Will message after a client disconnects. An unauthenticated or low-privileged attacker can connect to the broker, set a Last Will message with a payload for a restricted topic, perform an action that causes authorization failure (such as attempting an unauthorized publish), and when disconnected, the Last Will message will be published without authorization checks, reaching any subscribed clients. This bypasses the publish authorization policy entirely. The fix was released in version 0.35.1, which adds authorization checks to Last Will message publication.

Affected products

  • aedes aedes < 0.35.1

Timeline

  • 2018-08-06: disclosed: Security issue reported
  • 2018-08-07: patched: Fix merged in version 0.35.1
  • 2018-08-15: advisory: GitHub Security Advisory published

References

Related threats