Impact
Apache Lucene.Net.Replicator contains a path traversal flaw (CWE‑22) that allows a malicious replication source to supply a pathname that resolves outside the intended replication directory, resulting in arbitrary file writes on the client system. The vulnerability can be exploited to overwrite configuration files, replace executables, or inject malicious code, potentially leading to data integrity loss and enabling further compromise of the affected application.
Affected Systems
The flaw is present in versions 4.8.0-beta00005 through 4.8.0-beta00017 of Apache Lucene.Net.Replicator. The analysis infers that a project must expose a replication endpoint to external servers for exploitation to be possible. Any project that incorporates one of these beta releases and exposes such an endpoint is affected. Versions 4.8.0-beta00018 and later are unaffected.
Risk and Exploitability
The CVSS score of 8.9 indicates high severity, while the EPSS score of less than 1 % points to a low current exploitation rate and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a compromised or malicious replication server that delivers a crafted pathname; the analysis infers that control of the replication source is required to supply such a malicious value. Successful exploitation would permit the attacker to write to any file on the client system, creating a foothold for further attack. Organizations should assess exposure of replication endpoints and treat the risk as high for affected systems.
OpenCVE Enrichment