Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. Lucene.Net.Replicator
  4. ›
  5. CVE-2024-43383

CVE-2024-43383: Apache Lucene.Net.Replicator Deserialization of Untrusted Data vulnerability

October 31, 2024 (updated February 11, 2025)

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.

This issue affects Apache Lucene.NET’s Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016.

An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provided exception type. This can result in remote code execution or other potential unauthorized access.

Users are recommended to upgrade to version 4.8.0-beta00017, which fixes the issue.

References

  • github.com/advisories/GHSA-2qw8-ppr5-m96c
  • github.com/apache/lucenenet
  • github.com/apache/lucenenet/commit/1f61dd0fdb465e17141a79d22eb2f2bc02059acc
  • lists.apache.org/thread/wlz1p76dxpt4rl9o29voxjd5zl7717nh
  • nvd.nist.gov/vuln/detail/CVE-2024-43383

Code Behaviors & Features

Detect and mitigate CVE-2024-43383 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.8.0-beta00005 before 4.8.0-beta00017

Fixed versions

  • 4.8.0-beta00017

Solution

Upgrade to version 4.8.0-beta00017 or above.

Impact 8 HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

nuget/Lucene.Net.Replicator/CVE-2024-43383.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:28 +0000.