Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Affected products
Apache Software Foundation · Apache Qpid Broker-J