CVE-2022-42889: Apache commons_text(CVE-2022-42889) and commons_configuration (CVE-2022-33980) vulnerability
A flaw was found in Apache Commons Text packages 1.5 through 1.9. The affected versions allow an attacker to benefit from a variable interpolation process contained in Apache Commons Text, which can cause properties to be dynamically defined. Server applications are vulnerable to remote code execution (RCE) and unintentional contact with untrusted remote servers.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-42889?
CVE-2022-42889 is a vulnerability in Apache Commons Text that could allow a remote attacker to execute arbitrary code on the system.
What is the severity of CVE-2022-42889?
CVE-2022-42889 has a severity keyword of 'critical' and a severity value of 9.8.
How does CVE-2022-42889 affect Apache Commons Text?
CVE-2022-42889 affects Apache Commons Text by allowing properties to be dynamically evaluated and expanded, which can be exploited by an attacker to execute arbitrary code on the system.
How can I fix CVE-2022-42889 in Apache Commons Text?
To fix CVE-2022-42889 in Apache Commons Text, update to version 1.10.0 or later.
Where can I find more information about CVE-2022-42889?
You can find more information about CVE-2022-42889 on the GitHub page and the Red Hat security advisories linked in the references.