CVE-2022-42889 Details
Description
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 24, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache commons text | >= 1.5, < 1.10.0 |
CPE
Remediation
| |
| netapp bluexp | All versions |
CPE
Remediation
| |
| juniper security threat response manager | < 7.5.0 7.5.0 - 7.5.0 up1 7.5.0 up2 7.5.0 up3 |
CPE
Remediation
| |
| juniper jsa1500 | All versions |
CPE
Remediation
| |
| juniper jsa3500 | All versions |
CPE
Remediation
| |
| juniper jsa3800 | All versions |
CPE
Remediation
| |
| juniper jsa5500 | All versions |
CPE
Remediation
| |
| juniper jsa5800 | All versions |
CPE
Remediation
| |
| juniper jsa7500 | All versions |
CPE
Remediation
| |
| juniper jsa7800 | All versions |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 19, 2024 | CVE Modified | [email protected] |
| Apr 17, 2023 | Reanalysis | [email protected] |
| Mar 1, 2023 | Modified Analysis | [email protected] |
| Feb 15, 2023 | CVE Modified | [email protected] |
| Feb 15, 2023 | CVE Modified | [email protected] |
| Jan 11, 2023 | CVE Modified | [email protected] |
| Nov 29, 2022 | Modified Analysis | [email protected] |
| Oct 22, 2022 | CVE Modified | [email protected] |
| Oct 20, 2022 | CVE Modified | [email protected] |
| Oct 18, 2022 | CVE Modified | [email protected] |
| Oct 17, 2022 | Initial Analysis | [email protected] |
| Oct 13, 2022 | CVE Modified | [email protected] |
| Oct 13, 2022 | CVE Modified | [email protected] |