Critical Apache Commons Text Vulnerability Enables Remote Code Execution Attacks
ID: e54d67d4-a555-5b34-bb3b-f96255bc1de4
STIX ID: report--e54d67d4-a555-5b34-bb3b-f96255bc1de4
Feed Name: cybersecurityNews.com
A remote code execution vulnerability (CVE-2025-46295) was disclosed in Apache Commons Text versions prior to 1.10.0 due to unsafe interpolation features that can evaluate untrusted input; the flaw can allow arbitrary code execution or interaction with remote resources. Claris acknowledged the issue affecting FileMaker Server and states it has been mitigated in FileMaker Server 22.0.4 by updating the Commons Text library to a secure release (1.14.0); organizations are advised to scan dependencies and apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
