Deserialization of Untrusted Data Vulnerability Affecting Apache Lucene Replicator
CVE-2024-45772
What is CVE-2024-45772?
A deserialization of untrusted data vulnerability exists in the Apache Lucene Lucene's replicator module, impacting versions from 4.4.0 up to 9.12.0. The vulnerability is linked to the deprecated org.apache.lucene.replicator.http package, which poses risks when deployed in network-accessible implementations. User-defined clients utilizing HTTP libraries that access this API may trigger the deserialization issue. To mitigate this vulnerability on affected versions, Java serialization filters can be implemented (e.g., using -Djdk.serialFilter='!*' on the command line), ensuring functionality is not disrupted. Users are highly encouraged to upgrade to version 9.12.0 or later, which corrects this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Lucene Replicator 4.4.0 < 9.12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved