Impact
The vulnerability allows an attacker to inject arbitrary JEXL code into the Nutch REST API, leading to execution of arbitrary system commands. Because the API endpoint lacks authentication checks, the flaw can be exploited by any network user with access to the service, granting complete compromise of the host where Nutch runs. The weakness is defined by improper control of dynamically generated code and unsafe reflection, making the impact severe.
Affected Systems
Apache Nutch versions 1.11 through 1.22 are affected. The flaw resides in the Nutch Server component that exposes the REST API for search and indexing functions. Over the same version range, the Nutch Server remains a public-facing service.
Risk and Exploitability
The lack of authentication and ability to inject arbitrary JEXL expressions into the Nutch REST API makes the attack vector the exposed endpoint, allowing a network user to execute arbitrary system commands. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no confirmed public exploitation. Nevertheless, the high CVSS score of 8.8 and the potential for complete system compromise underscore a high severity risk for any machine that exposes the service.
OpenCVE Enrichment