Impact
Apache Qpid Broker-J contains a flaw that allows an attacker to send protocol messages before authentication, causing the broker to unboundedly cache symbol values. This results in rapid consumption of memory or CPU resources, eventually exhausting the broker’s resources and causing a denial of service. The weakness is identified as CWE‑770, reflecting unchecked resource consumption.
Affected Systems
Apache Qpid Broker‑J versions through 10.0.1 are affected. Versions 10.1.0 and later are not impacted.
Risk and Exploitability
The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, indicating a low publicly known exploitation probability. However, the CVSS score of 7.5 denotes a high severity risk to availability. The vulnerability can be triggered before authentication by sending crafted protocol messages, meaning unauthenticated users can initiate resource exhaustion if the broker is exposed to the network.
OpenCVE Enrichment