<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Lucene</title>
  <link>https://cvedaily.com/pages/tags/apache-lucene.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-lucene.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Lucene</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-43383 – Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43383</guid>
    <pubDate>Thu, 31 Oct 2024 10:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43383</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator.  This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016.  An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can provide a specially-crafted JSON response that is deserialized as an attacker-provi…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45772 – Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.

Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45772</guid>
    <pubDate>Mon, 30 Sep 2024 09:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45772</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.  This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected.  Users are recommended to upgrade to version 9.12.0, which fixes the issue.   The deserialization can only be…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-33647 – A vulnerability has been identified in Polarion ALM (All versions &lt; V2404.0). Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33647</guid>
    <pubDate>Tue, 14 May 2024 16:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-33647</strong></p>
  <p>A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-12629 – Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12629</guid>
    <pubDate>Sat, 14 Oct 2017 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-12629</strong></p>
  <p>Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12629">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
