Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrjq-9cmf-3h6f

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

EPSS

Процентиль: 31%
0.00383
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 7.4
nvd
22 дня назад

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

EPSS

Процентиль: 31%
0.00383
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-204