Impact
The vulnerability involves API that permits an unauthenticated user to command the Nutch Server to shut down or interrupt running jobs. This flaw causes denial of service by rendering the search indexing service unavailable. The weakness is represented by CWE-404 (Improper Resource Closure) and CWE-862 (Missing Authorization). The impact is confined to the Nutch service itself, but interruption of its indexing or search capabilities can affect downstream applications that rely on the service.
Affected Systems
The flaw exists in all supported Apache Nutch releases from version 1.10 through 1.22. The product is the Apache Nutch search platform component managed by the Apache Software Foundation. Upgrade to 1.23, where the Nutch Server component has been removed, eliminates the vulnerability. Systems still running one of the affected versions without monitoring must consider mitigating access restrictions.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation according to current predictive data. The critical severity, reflecting the potential for complete denial of service to the Nutch Server. The vulnerability is not listed in CISA’s KEV catalog. Because the REST API endpoint is reachable over the network and requires no authentication, any network actor that can reach the API could immediately issue shutdown or interruption commands. The likelihood of exploitation depends on exposure; a publicly reachable instance presents a high risk, while an internally firewalled instance reduces the threat but still allows local attackers to disrupt service. The likely attack vector is unauthenticated remote exploitation of the REST API.
OpenCVE Enrichment