[ 
https://issues.apache.org/jira/browse/TEXT-225?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Nikhil closed TEXT-225.
-----------------------
    Fix Version/s: 1.10.0
       Resolution: Not A Problem

Fixed in 1.10

> Apache Commons Arbitrary Code Execution Vulnerability (CVE-2022-42889)
> ----------------------------------------------------------------------
>
>                 Key: TEXT-225
>                 URL: https://issues.apache.org/jira/browse/TEXT-225
>             Project: Commons Text
>          Issue Type: Bug
>    Affects Versions: 1.5, 1.6, 1.7, 1.8, 1.9
>            Reporter: Nikhil
>            Priority: Major
>             Fix For: 1.10.0
>
>
> Apache Commons Text performs variable interpolation, allowing properties to 
> be dynamically evaluated and expanded. The standard format for interpolation 
> is "${prefix:name}", where "prefix" is used to locate an instance of 
> org.apache.commons.text.lookup.StringLookup that performs the interpolation. 
> Starting with version 1.5 and continuing through 1.9, the set of default 
> Lookup instances included interpolators that could result in arbitrary code 
> execution or contact with remote servers. These lookups are: - "script" - 
> execute expressions using the JVM script execution engine (javax.script) - 
> "dns" - resolve dns records - "url" - load values from urls, including from 
> remote servers Applications using the interpolation defaults in the affected 
> versions may be vulnerable to remote code execution or unintentional contact 
> with remote servers if untrusted configuration values are used. Users are 
> recommended to upgrade to Apache Commons Text 1.10.0, which disables the 
> problematic interpolators by default.
>  
> See [https://nvd.nist.gov/vuln/detail/cve-2022-42889] for more details..



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to