Deserialization of Untrusted Data Vulnerability Affecting Apache Lucene Replicator

CVE-2024-45772
8HIGH

Key Information

Vendor
Apache
Status
Apache Lucene Replicator
Vendor
CVE Published:
30 September 2024

Summary

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected. Users are recommended to upgrade to version 9.12.0, which fixes the issue. Java serialization filters (such as -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.

Affected Version(s)

Apache Lucene Replicator < 9.12.0

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: null to: 5.1 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Summ3r from Vidar-Team
Paul Irwin from Apache Lucene.NET
.