Описание
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
A flaw was found in Apache Qpid Proton-J. An authenticated attacker could exploit this by sending an excessive number of transfer frames, leading to uncontrolled resource usage and a potential denial of service (DoS). This vulnerability arises because the system does not properly govern the maximum number of transfer frames per incoming delivery.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | amq-broker-bin.zip | Fix deferred | ||
| Red Hat AMQ Broker 7 | amq-broker-maven-repository.zip | Fix deferred | ||
| Red Hat AMQ Clients | proton-j | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | proton-j | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-for-springboot-maven-repository.zip | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-maven-repository.zip | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-spring-boot-maven-repository.zip | Fix deferred | ||
| Red Hat build of Quarkus | proton-j | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | proton-j | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
It was not possible to govern the maximum number of transfer frames pe ...
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
EPSS
6.5 Medium
CVSS3