CyberRota Analysis
AI-GeneratedEclipse Milo versions 1.0.0 through 1.1.4 are vulnerable due to a flaw in the Call service that allows unauthorized execution of restricted methods when combined with permitted ones, potentially enabling low-privileged clients to bypass access controls. Organizations using these versions should prioritize remediation to prevent unauthorized access and potential exploitation of sensitive functionalities within their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
Related CVEs
Other vulnerabilities affecting the same vendor(s)