Impact
The vulnerability originates from missing authorization (CWE‑862) and the use of externally controlled input to select classes via reflection (CWE‑470) in the Nutch REST API. An unauthenticated attacker can send a specially crafted request to the Nutch Server endpoint, causing the server to load and execute attacker‑specified code. This enables full remote code execution on the host, compromising confidentiality, integrity, and availability.
Affected Systems
Apache Nutch versions 1.10 through 1.22 are affected. The flaw resides in the Nutch Server (REST API) component. The advisory recommends upgrading to version 1.23 or newer, which has removed the vulnerable Server.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 9.8, yet the vulnerability is not listed in CISA KEV, the lack of authentication together with unsafe reflection provides a direct exploitation path via HTTP. An attacker only needs network access to the REST API endpoint and no credentials. The high potential for arbitrary code execution and the absence of built‑in mitigations make this a high‑risk vulnerability for any exposed Nutch instance. Administrators should treat it as critical and act promptly.
OpenCVE Enrichment