<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2024-45772</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2024-45772</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>7</Number>
        <Date>2025-04-30T23:32:59Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-09-30T23:11:36Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-04-30T23:32:59Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2024-45772</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.

This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0.
The deprecated org.apache.lucene.replicator.http package is affected.
The org.apache.lucene.replicator.nrt package is not affected.

Users are recommended to upgrade to version 9.12.0, which fixes the issue.

 The deserialization can only be triggered if users actively deploy an network-accessible implementation and a corresponding client using a HTTP library that uses the API (e.g., a custom servlet and HTTPClient). Java serialization filters (such as  -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5" CPE="cpe:/o:suse:packagehub:15:sp5">SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6" CPE="cpe:/o:suse:packagehub:15:sp6">SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.5">
      <Branch Type="Product Name" Name="openSUSE Leap 15.5">
        <FullProductName ProductID="openSUSE Leap 15.5" CPE="cpe:/o:opensuse:leap:15.5">openSUSE Leap 15.5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="lucene">
      <FullProductName ProductID="lucene" CPE="cpe:2.3:a:apache:lucene:*:*:*:*:*:*:*:*">lucene</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-analyzers-common">
      <FullProductName ProductID="lucene-analyzers-common">lucene-analyzers-common</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-analyzers-smartcn">
      <FullProductName ProductID="lucene-analyzers-smartcn">lucene-analyzers-smartcn</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-analyzers-stempel">
      <FullProductName ProductID="lucene-analyzers-stempel">lucene-analyzers-stempel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-backward-codecs">
      <FullProductName ProductID="lucene-backward-codecs">lucene-backward-codecs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-classification">
      <FullProductName ProductID="lucene-classification">lucene-classification</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-codecs">
      <FullProductName ProductID="lucene-codecs">lucene-codecs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-core">
      <FullProductName ProductID="lucene-core">lucene-core</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-facet">
      <FullProductName ProductID="lucene-facet">lucene-facet</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-grouping">
      <FullProductName ProductID="lucene-grouping">lucene-grouping</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-highlighter">
      <FullProductName ProductID="lucene-highlighter">lucene-highlighter</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-join">
      <FullProductName ProductID="lucene-join">lucene-join</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-memory">
      <FullProductName ProductID="lucene-memory">lucene-memory</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-misc">
      <FullProductName ProductID="lucene-misc">lucene-misc</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-monitor">
      <FullProductName ProductID="lucene-monitor">lucene-monitor</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-queries">
      <FullProductName ProductID="lucene-queries">lucene-queries</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-queryparser">
      <FullProductName ProductID="lucene-queryparser">lucene-queryparser</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-sandbox">
      <FullProductName ProductID="lucene-sandbox">lucene-sandbox</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-spatial">
      <FullProductName ProductID="lucene-spatial">lucene-spatial</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lucene-spatial3d">
      <FullProductName ProductID="lucene-spatial3d">lucene-spatial3d</FullProductName>
    </Branch>
    <Relationship ProductReference="lucene-analyzers-common" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-analyzers-common">lucene-analyzers-common as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-smartcn" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-analyzers-smartcn">lucene-analyzers-smartcn as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-core" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-core">lucene-core as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-misc" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-misc">lucene-misc as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queries" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-queries">lucene-queries as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queryparser" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-queryparser">lucene-queryparser as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-sandbox" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-sandbox">lucene-sandbox as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene">lucene as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-common" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-analyzers-common">lucene-analyzers-common as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-smartcn" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-analyzers-smartcn">lucene-analyzers-smartcn as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-core" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-core">lucene-core as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-misc" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-misc">lucene-misc as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queries" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-queries">lucene-queries as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queryparser" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-queryparser">lucene-queryparser as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-sandbox" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-sandbox">lucene-sandbox as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene">lucene as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-common" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-analyzers-common">lucene-analyzers-common as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-smartcn" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-analyzers-smartcn">lucene-analyzers-smartcn as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-stempel" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-analyzers-stempel">lucene-analyzers-stempel as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-backward-codecs" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-backward-codecs">lucene-backward-codecs as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-classification" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-classification">lucene-classification as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-codecs" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-codecs">lucene-codecs as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-core" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-core">lucene-core as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-facet" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-facet">lucene-facet as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-grouping" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-grouping">lucene-grouping as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-highlighter" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-highlighter">lucene-highlighter as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-join" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-join">lucene-join as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-memory" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-memory">lucene-memory as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-misc" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-misc">lucene-misc as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-monitor" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-monitor">lucene-monitor as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queries" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-queries">lucene-queries as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queryparser" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-queryparser">lucene-queryparser as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-sandbox" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-sandbox">lucene-sandbox as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-spatial" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-spatial">lucene-spatial as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-spatial3d" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene-spatial3d">lucene-spatial3d as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:lucene">lucene as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-common" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-analyzers-common">lucene-analyzers-common as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-smartcn" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-analyzers-smartcn">lucene-analyzers-smartcn as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-analyzers-stempel" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-analyzers-stempel">lucene-analyzers-stempel as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-backward-codecs" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-backward-codecs">lucene-backward-codecs as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-classification" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-classification">lucene-classification as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-codecs" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-codecs">lucene-codecs as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-core" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-core">lucene-core as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-facet" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-facet">lucene-facet as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-grouping" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-grouping">lucene-grouping as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-highlighter" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-highlighter">lucene-highlighter as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-join" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-join">lucene-join as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-memory" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-memory">lucene-memory as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-misc" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-misc">lucene-misc as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-monitor" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-monitor">lucene-monitor as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queries" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-queries">lucene-queries as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-queryparser" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-queryparser">lucene-queryparser as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-sandbox" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-sandbox">lucene-sandbox as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-spatial" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-spatial">lucene-spatial as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene-spatial3d" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene-spatial3d">lucene-spatial3d as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="lucene" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:lucene">lucene as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.

This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0.
The deprecated org.apache.lucene.replicator.http package is affected.
The org.apache.lucene.replicator.nrt package is not affected.

Users are recommended to upgrade to version 9.12.0, which fixes the issue.

 The deserialization can only be triggered if users actively deploy an network-accessible implementation and a corresponding client using a HTTP library that uses the API (e.g., a custom servlet and HTTPClient). Java serialization filters (such as  -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.</Note>
    </Notes>
    <CVE>CVE-2024-45772</CVE>
    <ProductStatuses>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-analyzers-common</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-analyzers-smartcn</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-core</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-misc</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-queries</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-queryparser</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:lucene-sandbox</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-analyzers-common</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-analyzers-smartcn</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-core</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-misc</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-queries</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-queryparser</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:lucene-sandbox</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-analyzers-common</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-analyzers-smartcn</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-analyzers-stempel</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-backward-codecs</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-classification</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-codecs</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-core</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-facet</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-grouping</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-highlighter</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-join</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-memory</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-misc</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-monitor</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-queries</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-queryparser</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-sandbox</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-spatial</ProductID>
        <ProductID>openSUSE Leap 15.5:lucene-spatial3d</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-analyzers-common</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-analyzers-smartcn</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-analyzers-stempel</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-backward-codecs</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-classification</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-codecs</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-core</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-facet</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-grouping</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-highlighter</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-join</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-memory</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-misc</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-monitor</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-queries</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-queryparser</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-sandbox</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-spatial</ProductID>
        <ProductID>openSUSE Leap 15.6:lucene-spatial3d</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
