Impact
The vulnerability in Apache Qpid Proton-J prevents limiting the number of transfer frames that can be received for a delivery, allowing an authenticated user to send many frames and exhaust server resources, potentially causing a denial of service.
Affected Systems
Affected systems are instances of Apache Qpid Proton‑J version 0.34.1 and earlier. The issue is resolved in version 0.35.0.
Risk and Exploitability
The vulnerability can only be exploited by an attacker who has authenticated access to the Proton‑J server; no exploit evidence is available and the EPSS score is not available. While visibility into the likelihood of exploitation is limited, the impact of exhausting resources could be severe and the CVSS score is 6.5, indicating moderate severity.
OpenCVE Enrichment