Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-45772

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected. Users are recommended to upgrade to version 9.12.0, which fixes the issue. The deserialization can only be triggered if users actively deploy an network-accessible implementation and a corresponding client using a HTTP library that uses the API (e.g., a custom servlet and HTTPClient). Java serialization filters (such as -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.2%
CVSS Severity
CVSS v3 Score 5.1
Products affected by CVE-2024-45772
  • Apache » Lucene » Version: 4.10.0
    cpe:2.3:a:apache:lucene:4.10.0
  • Apache » Lucene » Version: 4.10.1
    cpe:2.3:a:apache:lucene:4.10.1
  • Apache » Lucene » Version: 4.10.2
    cpe:2.3:a:apache:lucene:4.10.2
  • Apache » Lucene » Version: 4.10.3
    cpe:2.3:a:apache:lucene:4.10.3
  • Apache » Lucene » Version: 4.10.4
    cpe:2.3:a:apache:lucene:4.10.4
  • Apache » Lucene » Version: 4.4.0
    cpe:2.3:a:apache:lucene:4.4.0
  • Apache » Lucene » Version: 4.5.0
    cpe:2.3:a:apache:lucene:4.5.0
  • Apache » Lucene » Version: 4.5.1
    cpe:2.3:a:apache:lucene:4.5.1
  • Apache » Lucene » Version: 4.6.0
    cpe:2.3:a:apache:lucene:4.6.0
  • Apache » Lucene » Version: 4.6.1
    cpe:2.3:a:apache:lucene:4.6.1
  • Apache » Lucene » Version: 4.7.0
    cpe:2.3:a:apache:lucene:4.7.0
  • Apache » Lucene » Version: 4.7.1
    cpe:2.3:a:apache:lucene:4.7.1
  • Apache » Lucene » Version: 4.7.2
    cpe:2.3:a:apache:lucene:4.7.2
  • Apache » Lucene » Version: 4.8.0
    cpe:2.3:a:apache:lucene:4.8.0
  • Apache » Lucene » Version: 4.8.1
    cpe:2.3:a:apache:lucene:4.8.1
  • Apache » Lucene » Version: 4.9.0
    cpe:2.3:a:apache:lucene:4.9.0
  • Apache » Lucene » Version: 4.9.1
    cpe:2.3:a:apache:lucene:4.9.1
  • Apache » Lucene » Version: 5.0.0
    cpe:2.3:a:apache:lucene:5.0.0
  • Apache » Lucene » Version: 5.1.0
    cpe:2.3:a:apache:lucene:5.1.0
  • Apache » Lucene » Version: 5.2.0
    cpe:2.3:a:apache:lucene:5.2.0
  • Apache » Lucene » Version: 5.2.1
    cpe:2.3:a:apache:lucene:5.2.1
  • Apache » Lucene » Version: 5.3.0
    cpe:2.3:a:apache:lucene:5.3.0
  • Apache » Lucene » Version: 5.3.1
    cpe:2.3:a:apache:lucene:5.3.1
  • Apache » Lucene » Version: 5.3.2
    cpe:2.3:a:apache:lucene:5.3.2
  • Apache » Lucene » Version: 5.4.0
    cpe:2.3:a:apache:lucene:5.4.0
  • Apache » Lucene » Version: 5.4.1
    cpe:2.3:a:apache:lucene:5.4.1
  • Apache » Lucene » Version: 5.5.0
    cpe:2.3:a:apache:lucene:5.5.0
  • Apache » Lucene » Version: 5.5.1
    cpe:2.3:a:apache:lucene:5.5.1
  • Apache » Lucene » Version: 5.5.2
    cpe:2.3:a:apache:lucene:5.5.2
  • Apache » Lucene » Version: 5.5.3
    cpe:2.3:a:apache:lucene:5.5.3
  • Apache » Lucene » Version: 5.5.4
    cpe:2.3:a:apache:lucene:5.5.4
  • Apache » Lucene » Version: 6.0.0
    cpe:2.3:a:apache:lucene:6.0.0
  • Apache » Lucene » Version: 6.0.1
    cpe:2.3:a:apache:lucene:6.0.1
  • Apache » Lucene » Version: 6.1.0
    cpe:2.3:a:apache:lucene:6.1.0
  • Apache » Lucene » Version: 6.2.0
    cpe:2.3:a:apache:lucene:6.2.0
  • Apache » Lucene » Version: 6.2.1
    cpe:2.3:a:apache:lucene:6.2.1
  • Apache » Lucene » Version: 6.3.0
    cpe:2.3:a:apache:lucene:6.3.0
  • Apache » Lucene » Version: 6.4.0
    cpe:2.3:a:apache:lucene:6.4.0
  • Apache » Lucene » Version: 6.4.1
    cpe:2.3:a:apache:lucene:6.4.1
  • Apache » Lucene » Version: 6.4.2
    cpe:2.3:a:apache:lucene:6.4.2
  • Apache » Lucene » Version: 6.5.0
    cpe:2.3:a:apache:lucene:6.5.0
  • Apache » Lucene » Version: 6.5.1
    cpe:2.3:a:apache:lucene:6.5.1
  • Apache » Lucene » Version: 6.6.0
    cpe:2.3:a:apache:lucene:6.6.0
  • Apache » Lucene » Version: 6.6.1
    cpe:2.3:a:apache:lucene:6.6.1
  • Apache » Lucene » Version: 6.6.3
    cpe:2.3:a:apache:lucene:6.6.3
  • Apache » Lucene » Version: 6.6.4
    cpe:2.3:a:apache:lucene:6.6.4
  • Apache » Lucene » Version: 6.6.5
    cpe:2.3:a:apache:lucene:6.6.5
  • Apache » Lucene » Version: 6.6.6
    cpe:2.3:a:apache:lucene:6.6.6
  • Apache » Lucene » Version: 7.0.0
    cpe:2.3:a:apache:lucene:7.0.0
  • Apache » Lucene » Version: 7.0.1
    cpe:2.3:a:apache:lucene:7.0.1
  • Apache » Lucene » Version: 7.1.0
    cpe:2.3:a:apache:lucene:7.1.0
  • Apache » Lucene » Version: 7.2.0
    cpe:2.3:a:apache:lucene:7.2.0
  • Apache » Lucene » Version: 7.2.1
    cpe:2.3:a:apache:lucene:7.2.1
  • Apache » Lucene » Version: 7.3.0
    cpe:2.3:a:apache:lucene:7.3.0
  • Apache » Lucene » Version: 7.3.1
    cpe:2.3:a:apache:lucene:7.3.1
  • Apache » Lucene » Version: 7.4.0
    cpe:2.3:a:apache:lucene:7.4.0
  • Apache » Lucene » Version: 7.5.0
    cpe:2.3:a:apache:lucene:7.5.0
  • Apache » Lucene » Version: 7.6.0
    cpe:2.3:a:apache:lucene:7.6.0
  • Apache » Lucene » Version: 7.7.0
    cpe:2.3:a:apache:lucene:7.7.0
  • Apache » Lucene » Version: 7.7.1
    cpe:2.3:a:apache:lucene:7.7.1
  • Apache » Lucene » Version: 7.7.2
    cpe:2.3:a:apache:lucene:7.7.2
  • Apache » Lucene » Version: 7.7.3
    cpe:2.3:a:apache:lucene:7.7.3
  • Apache » Lucene » Version: 8.0.0
    cpe:2.3:a:apache:lucene:8.0.0
  • Apache » Lucene » Version: 8.1.0
    cpe:2.3:a:apache:lucene:8.1.0
  • Apache » Lucene » Version: 8.1.1
    cpe:2.3:a:apache:lucene:8.1.1
  • Apache » Lucene » Version: 8.10.0
    cpe:2.3:a:apache:lucene:8.10.0
  • Apache » Lucene » Version: 8.10.1
    cpe:2.3:a:apache:lucene:8.10.1
  • Apache » Lucene » Version: 8.11.0
    cpe:2.3:a:apache:lucene:8.11.0
  • Apache » Lucene » Version: 8.11.1
    cpe:2.3:a:apache:lucene:8.11.1
  • Apache » Lucene » Version: 8.11.2
    cpe:2.3:a:apache:lucene:8.11.2
  • Apache » Lucene » Version: 8.11.3
    cpe:2.3:a:apache:lucene:8.11.3
  • Apache » Lucene » Version: 8.11.4
    cpe:2.3:a:apache:lucene:8.11.4
  • Apache » Lucene » Version: 8.2.0
    cpe:2.3:a:apache:lucene:8.2.0
  • Apache » Lucene » Version: 8.3.0
    cpe:2.3:a:apache:lucene:8.3.0
  • Apache » Lucene » Version: 8.3.1
    cpe:2.3:a:apache:lucene:8.3.1
  • Apache » Lucene » Version: 8.4.0
    cpe:2.3:a:apache:lucene:8.4.0
  • Apache » Lucene » Version: 8.4.1
    cpe:2.3:a:apache:lucene:8.4.1
  • Apache » Lucene » Version: 8.5.0
    cpe:2.3:a:apache:lucene:8.5.0
  • Apache » Lucene » Version: 8.5.1
    cpe:2.3:a:apache:lucene:8.5.1
  • Apache » Lucene » Version: 8.5.2
    cpe:2.3:a:apache:lucene:8.5.2
  • Apache » Lucene » Version: 8.6.0
    cpe:2.3:a:apache:lucene:8.6.0
  • Apache » Lucene » Version: 8.6.1
    cpe:2.3:a:apache:lucene:8.6.1
  • Apache » Lucene » Version: 8.6.2
    cpe:2.3:a:apache:lucene:8.6.2
  • Apache » Lucene » Version: 8.6.3
    cpe:2.3:a:apache:lucene:8.6.3
  • Apache » Lucene » Version: 8.7.0
    cpe:2.3:a:apache:lucene:8.7.0
  • Apache » Lucene » Version: 8.8.0
    cpe:2.3:a:apache:lucene:8.8.0
  • Apache » Lucene » Version: 8.8.1
    cpe:2.3:a:apache:lucene:8.8.1
  • Apache » Lucene » Version: 8.8.2
    cpe:2.3:a:apache:lucene:8.8.2
  • Apache » Lucene » Version: 8.9.0
    cpe:2.3:a:apache:lucene:8.9.0
  • Apache » Lucene » Version: 9.0.0
    cpe:2.3:a:apache:lucene:9.0.0
  • Apache » Lucene » Version: 9.1.0
    cpe:2.3:a:apache:lucene:9.1.0
  • Apache » Lucene » Version: 9.10.0
    cpe:2.3:a:apache:lucene:9.10.0
  • Apache » Lucene » Version: 9.11.0
    cpe:2.3:a:apache:lucene:9.11.0
  • Apache » Lucene » Version: 9.11.1
    cpe:2.3:a:apache:lucene:9.11.1
  • Apache » Lucene » Version: 9.2.0
    cpe:2.3:a:apache:lucene:9.2.0
  • Apache » Lucene » Version: 9.3.0
    cpe:2.3:a:apache:lucene:9.3.0
  • Apache » Lucene » Version: 9.4.0
    cpe:2.3:a:apache:lucene:9.4.0
  • Apache » Lucene » Version: 9.4.1
    cpe:2.3:a:apache:lucene:9.4.1
  • Apache » Lucene » Version: 9.4.2
    cpe:2.3:a:apache:lucene:9.4.2
  • Apache » Lucene » Version: 9.5.0
    cpe:2.3:a:apache:lucene:9.5.0
  • Apache » Lucene » Version: 9.6.0
    cpe:2.3:a:apache:lucene:9.6.0
  • Apache » Lucene » Version: 9.7.0
    cpe:2.3:a:apache:lucene:9.7.0
  • Apache » Lucene » Version: 9.8.0
    cpe:2.3:a:apache:lucene:9.8.0
  • Apache » Lucene » Version: 9.9.0
    cpe:2.3:a:apache:lucene:9.9.0
  • Apache » Lucene » Version: 9.9.1
    cpe:2.3:a:apache:lucene:9.9.1
  • Apache » Lucene » Version: 9.9.2
    cpe:2.3:a:apache:lucene:9.9.2


Contact Us

Shodan ® - All rights reserved