Impact
The vulnerability prevents the governance of maximum transfer frames per incoming delivery, allowing an authenticated attacker to deliver an excessive number of transfer frames, leading to elevated resource consumption and a potential denial of service. The impact is a loss of availability due to resource exhaustion, affecting system stability for affected users.
Affected Systems
The affected product is Apache Qpid ProtonJ2 from the Apache Software Foundation. All releases through 1.1.0 are vulnerable, and the issue is fixed in version 1.2.0.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this vulnerability. It requires authentication, so only authorized users who can establish connections can exploit the resource exhaustion. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV, suggesting that exploitation would likely require intentional abuse rather than exploitation of a default or publicly exposed interface.
OpenCVE Enrichment