PT-2024-7646 · Apache · Apache Lucene.Net.Replicator
Apache Lucene
+2
·
Published
2024-10-08
·
Updated
2024-11-05
·
CVE-2024-43383
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Lucene.Net.Replicator versions 4.8.0-beta00005 through 4.8.0-beta00016
Description
This issue is related to the deserialization of untrusted data, which can result in remote code execution or other potential unauthorized access. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type.
Recommendations
To resolve the issue, upgrade to version 4.8.0-beta00017, which fixes the issue. As a temporary workaround, consider restricting access to the vulnerable Replicator library to minimize the risk of exploitation. Avoid using the vulnerable library until the issue is resolved.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Lucene.Net.Replicator