← Back

CVE-2024-43383

nvd nist
Published: Oct 31, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access. Users are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.

Affected (12)

Products: Apache: Lucene.net
1 product
Lucene.net
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 4.8.0 beta00005
Version 4.8.0 beta00006
Version 4.8.0 beta00007
Version 4.8.0 beta00008
Version 4.8.0 beta00009
Version 4.8.0 beta00010
Version 4.8.0 beta00011
Version 4.8.0 beta00012
Version 4.8.0 beta00013
Version 4.8.0 beta00014
Version 4.8.0 beta00015
Version 4.8.0 beta00016

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.