Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-60007

Опубликовано: 04 авг. 2026
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:*
Версия от 0.6.0 (включая) до 1.1.5 (исключая)

EPSS

Процентиль: 32%
0.00383
Низкий

7.4 High

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 7.4
github
21 день назад

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

EPSS

Процентиль: 32%
0.00383
Низкий

7.4 High

CVSS3

Дефекты

CWE-204