CVE-2022-42889
CVSS v3
9.8
CRITICAL
Score EPSS
99.9 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
Détails techniques
- Publiée le
- 2022-10-13
- Exploit-DB
- EDB-52261
Questions fréquentes
Qu’est-ce que CVE-2022-42889 ?
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
CVE-2022-42889 est-elle activement exploitée ?
Aucune exploitation active de CVE-2022-42889 n’est confirmée. Son score EPSS était de 99.9 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2022-42889 ?
CVE-2022-42889 a un score de base CVSS v3 de 9.8 (gravité CRITICAL).
CVE-2022-42889 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2022 à trier
Classées par probabilité d’exploitation (EPSS).