CVE-2022-42889

Scores

EPSS

0.943high94.3%
0%20%40%60%80%100%

Percentile: 94.3%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is “${prefix:name}”, where “prefix” is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - “script” - execute expressions using the JVM script execution engine (javax.script) - “dns” - resolve dns records - “url” - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

anchore_overridesdebiannvdredhatubuntu

CWEs

94CWE-94

Related Vulnerabilities

Exploits

Exploit ID: 52261

Source: exploitdb

URL: https://www.exploit-db.com/exploits/52261

Exploit ID: CVE-2022-42889

Source: github-poc

URL: https://github.com/KosmicOwl045/ICT287-CVE-2022-42889

Recommendations

Source: nvd

All Apache Commons Text users should upgrade to the latest version:
# emerge –sync
# emerge –ask –oneshot –verbose “>=dev-java/commons-text-1.10.0”

URL: https://security.gentoo.org/glsa/202301-05

Vulnerable Software (33)

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:apache:commons-text:*:*:*:*:*:maven:*:*",          "versionEndExcluding": "1.10",          "versionStartInclud...

Source: anchore_overrides

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:com.guicedee.services:commons-text:*:*:*:*:*:maven:*:*",          "versionEndIncluding": "1.2.2.1-jre17"      ...

Source: anchore_overrides

Type: Configuration

Product: candlepin

Operating System: rhel

Trait:
{  "fixed": "4.1.18-1.el8sat"}

Source: redhat

Type: Configuration

Product: candlepin

Operating System: rhel

Trait:
{  "fixed": "4.2.13-1.el8sat"}

Source: redhat

Type: Configuration

Product: commons-text

Operating System: debian

Trait:
{  "fixed": "1.10.0-1"}

Source: debian

Type: Configuration

Product: commons-text

Operating System: debian bullseye 11

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: commons-text

Operating System: ubuntu focal 20.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu jammy 22.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu kinetic 22.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu lunar 23.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu mantic 23.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu noble 24.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu oracular 24.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu plucky 25.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu questing 25.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu trusty 14.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: commons-text

Operating System: ubuntu xenial 16.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{  "fixed": "4.13.1684911916-1.el8"}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{  "fixed": "4.13.1698292274-1.el8"}

Source: redhat

Type: Configuration

Product: jenkins-2-plugins

Operating System: rhel

Trait:
{  "fixed": "4.13.1706516346-1.el8"}

Source: redhat