Impact
A race condition exists in the core/user.py component of the Telemetry Endpoint when the argument vId is manipulated. This flaw can be triggered remotely, though its exploitation is described as highly complex and difficult. The vulnerability may lead to inconsistent or corrupted telemetry data, which can degrade service availability or correctness.
Affected Systems
The affected product is jofpin trape, version 2.0. No other versions or products are specified in the available data.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The race condition requires an attacker to remotely manipulate vId concurrently, making successful exploitation challenging. However, the flaw is publicly disclosed and could be targeted by sophisticated attackers through the telemetry endpoint.
OpenCVE Enrichment