PT-2024-7646 · Apache · Apache Lucene.Net.Replicator

Apache Lucene

+2

·

Published

2024-10-08

·

Updated

2024-11-05

·

CVE-2024-43383

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Lucene.Net.Replicator versions 4.8.0-beta00005 through 4.8.0-beta00016
Description This issue is related to the deserialization of untrusted data, which can result in remote code execution or other potential unauthorized access. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type.
Recommendations To resolve the issue, upgrade to version 4.8.0-beta00017, which fixes the issue. As a temporary workaround, consider restricting access to the vulnerable Replicator library to minimize the risk of exploitation. Avoid using the vulnerable library until the issue is resolved.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-09087
CVE-2024-43383
GHSA-2QW8-PPR5-M96C

Affected Products

Apache Lucene.Net.Replicator