Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Update Apache Software Foundation/Apache Lucene.Net to 4.8.0-beta00018 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server affects Apache Software Foundation/Apache Lucene.Net (generic). Severity is high. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache Lucene.Netgeneric | >=4.8.0-beta00005 <4.8.0-beta00018 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Update Apache Software Foundation/Apache Lucene.Net to 4.8.0-beta00018 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server affects Apache Software Foundation/Apache Lucene.Net (generic). Severity is high. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache Lucene.Netgeneric | >=4.8.0-beta00005 <4.8.0-beta00018 |
| 4.8.0-beta00018 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 4.8.0-beta00018 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard