Impact
An untrusted data deserialization flaw exists in Apache Lucy that allows an attacker to send a specially crafted Storable::thaw payload to the LucyX::Remote::SearchServer endpoint. This flaw can be leveraged to execute arbitrary code or trigger a denial of service. The flaw is present in all versions of Lucy, and because the project has been retired, no vendor patch will be released. Users must therefore secure the component or migrate away.
Affected Systems
The affected product is Apache Lucy developed by the Apache Software Foundation. All released versions of Lucy are impacted. The project is currently retired and will not receive updates.
Risk and Exploitability
The attack vector is remote and unauthenticated, meaning that anyone who can reach the SearchServer interface can exploit the flaw. The absence of a public patch and the project's retirement elevate the risk. While no EPSS score is published and the vulnerability is not listed in the KEV catalog, the potential for remote code execution implies a high severity. Mitigation requires restricting access or replacing the software altogether.
OpenCVE Enrichment