Impact
An untrusted data deserialization flaw exists in Apache Lucy that allows an attacker to send a specially crafted Storable::thaw payload to the LucyX::Remote::SearchServer endpoint. This flaw can be leveraged to execute arbitrary code or trigger a denial of service. The flaw is present in all versions of Lucy, and because the project has been retired, no vendor patch will be released. Users must therefore secure the component or migrate away.
Affected Systems
The affected product is Apache Lucy developed by the Apache Software Foundation. All released versions of Lucy are impacted. The project is currently retired and will not receive updates.
Risk and Exploitability
The attack vector is remote and unauthenticated, meaning that anyone who can reach the SearchServer interface can exploit the flaw. The absence of a public patch and the project's retirement elevate the risk. The CVSS score of 9.8 underscores a critical severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. Because the vulnerability is not listed in CISA KEV and no vendor patch exists, mitigating actions such as restricting access or replacing the software remain the only effective measures.
OpenCVE Enrichment