Описание
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
Ссылки
- Patch
- Issue TrackingPatchVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 1.1.5 (исключая)
cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:*
EPSS
Процентиль: 22%
0.00298
Низкий
7.5 High
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 7.5
github
7 дней назад
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
EPSS
Процентиль: 22%
0.00298
Низкий
7.5 High
CVSS3
Дефекты
CWE-863