Impact
Apache Lucene.Net.Replicator contains a path write to the client system. This flaw stems from improper pathname restriction (CWE-22), potentially enabling overwriting of any file within the initiates replication. The impact is the loss of data integrity and the ability for an attacker to place malicious files on the client, which could influence application behavior or compromise the system.
Affected Systems
The affected module of Apache Lucene.Net, a .NET library used for search indexes. Versions from 4.8.0-beta00005 up to, but not including, 4.8.0-beta00018 are vulnerable. Organizations deploying any of these beta releases are urged to update to 4.8.0-beta00018 or later.
Risk and Exploitability
The flaw scores a CVSS of 8.9, indicating high severity. The EPSS score is less than 1%, suggesting the likelihood of exploitation is very low at present is not present in the CISA KEV list. It is inferred that the attack vector is network-based, requiring a malicious server to initiate a replication session to the affected client. Successful exploitation would give the attacker the ability to compromise files on the client during replication.
OpenCVE Enrichment