Impact
The vulnerability is a path‑traversal flaw that allows an unauthenticated attacker to read any file on the host where the Lucene.Net.Replicator component runs. By manipulating pathname components, the replication server can access files outside its designated directory, exposing configuration files or other sensitive data and compromising confidentiality. The flaw is active for builds in which the path resolution logic is unguarded, enabling direct access to system files when the replication service is reachable.
Affected Systems
Apache Lucene.Net.Replicator, released by the Apache Software Foundation, is affected from version 4.8.0-beta00005 through 4.8.0-beta00017.
Risk and Exploitability
The CVSS score of 8.9 marks this issue as high severity, yet the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, the replication service must be accessible over the network for exploitation, so the risk is greatest when the service is exposed to untrusted networks. Monitoring for replication API requests and limiting network exposure can reduce the risk of successful exploitation.
OpenCVE Enrichment