Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qw8-ppr5-m96c

Опубликовано: 31 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8

Описание

Apache Lucene.Net.Replicator Deserialization of Untrusted Data vulnerability

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.

This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016.

An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access.

Users are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.

Пакеты

Наименование

Lucene.Net.Replicator

nuget
Затронутые версииВерсия исправления

>= 4.8.0-beta00005, < 4.8.0-beta00017

4.8.0-beta00017

EPSS

Процентиль: 87%
0.0354
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8
nvd
больше 1 года назад

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access. Users are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.

CVSS3: 8
fstec
больше 1 года назад

Уязвимость утилиты репликации файлов Lucene.Net.Replicator библиотеки полнотекстового поиска для платформы .NET Apache Lucene.Net, позволяющая нарушителю выполнить произвольный код и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 87%
0.0354
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-502