CVE-2024-43383

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.

This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016.

An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access.


Users are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
apacheCNA
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
apachelucene.net
4.8.0:beta00005
apachelucene.net
4.8.0:beta00006
apachelucene.net
4.8.0:beta00007
apachelucene.net
4.8.0:beta00008
apachelucene.net
4.8.0:beta00009
apachelucene.net
4.8.0:beta00010
apachelucene.net
4.8.0:beta00011
apachelucene.net
4.8.0:beta00012
apachelucene.net
4.8.0:beta00013
apachelucene.net
4.8.0:beta00014
apachelucene.net
4.8.0:beta00015
apachelucene.net
4.8.0:beta00016
𝑥
= Vulnerable software versions