[
https://issues.apache.org/jira/browse/TEXT-225?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Nikhil closed TEXT-225.
-----------------------
Fix Version/s: 1.10.0
Resolution: Not A Problem
Fixed in 1.10
> Apache Commons Arbitrary Code Execution Vulnerability (CVE-2022-42889)
> ----------------------------------------------------------------------
>
> Key: TEXT-225
> URL: https://issues.apache.org/jira/browse/TEXT-225
> Project: Commons Text
> Issue Type: Bug
> Affects Versions: 1.5, 1.6, 1.7, 1.8, 1.9
> Reporter: Nikhil
> Priority: Major
> Fix For: 1.10.0
>
>
> Apache Commons Text performs variable interpolation, allowing properties to
> be dynamically evaluated and expanded. The standard format for interpolation
> is "${prefix:name}", where "prefix" is used to locate an instance of
> org.apache.commons.text.lookup.StringLookup that performs the interpolation.
> Starting with version 1.5 and continuing through 1.9, the set of default
> Lookup instances included interpolators that could result in arbitrary code
> execution or contact with remote servers. These lookups are: - "script" -
> execute expressions using the JVM script execution engine (javax.script) -
> "dns" - resolve dns records - "url" - load values from urls, including from
> remote servers Applications using the interpolation defaults in the affected
> versions may be vulnerable to remote code execution or unintentional contact
> with remote servers if untrusted configuration values are used. Users are
> recommended to upgrade to Apache Commons Text 1.10.0, which disables the
> problematic interpolators by default.
>
> See [https://nvd.nist.gov/vuln/detail/cve-2022-42889] for more details..
--
This message was sent by Atlassian Jira
(v8.20.10#820010)