Text4Shell: CVE-2022-42889 in Apache Commons Text Explained
ID: e8e19c17-6801-55da-ad8d-7eae4818c549
STIX ID: report--e8e19c17-6801-55da-ad8d-7eae4818c549
Feed Name: Aqua Security Blog
Apache Commons Text contains CVE-2022-42889 ("Text4Shell"), a vulnerability in the StringSubstitutor default interpolators that can lead to remote code execution (via the "script" lookup) or unintended remote requests (via "dns" and "url"). The issue affects Commons Text versions 1.5–1.9, shows dependence on specific JDK versions for exploitability, and—while currently no active exploitation was observed by the authors—organizations should upgrade to version 1.10 and scan dependencies to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
