CVE-2022-42889: vulnerability in Apache Commons Text
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
Published · Updated
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 100%
from disclosure to weapon4 days
Published on NVDOct 13
1st PoC+4d
metasploitOct 13
VulnCheck+91d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesVulnCheck
93 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
4 products (5 components)
Red Hat OpenShift Container Platform 3.11 · Red Hat Integration Camel K 1 · Red Hat JBoss Enterprise Application Platform 7 · Red Hat JBoss Enterprise Application Platform Expansion Pack
workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
Fixed
18 products (129 components)
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 · OpenShift Developer Tools and Services for OCP 4.12 · OpenShift Developer Tools and Services for OCP 4.13 · and others 13
Not affected
20 products (2,385 components) — because the vulnerable code is not present in the product
Red Hat Satellite 6.13 for RHEL 8 · Red Hat OpenShift Container Platform 4.10 · Red Hat OpenShift Container Platform 4.9 · Red Hat Satellite 6.12 for RHEL 8 · OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 · and others 15
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
Affected products
Apache Software Foundation · Apache Commons Textpublic PoCs found — 93
exploitdbwww.exploit-db.com/exploits/52261unverifiedgithubgithub.com/karthikuj/cve-2022-42889-text4shell-docker★ 76githubgithub.com/kljunowsky/CVE-2022-42889-text4shell★ 58githubgithub.com/ClickCyber/cve-2022-42889★ 40githubgithub.com/SeanWrightSec/CVE-2022-42889-PoC★ 35githubgithub.com/f0ng/text4shellburpscanner★ 20githubgithub.com/cxzero/CVE-2022-42889-text4shell★ 20githubgithub.com/cryxnet/CVE-2022-42889-RCE★ 15githubgithub.com/alealeluyah/CVE-2022-42889-Text4Shell-POC★ 13githubgithub.com/korteke/CVE-2022-42889-POC★ 10githubgithub.com/ifconfig-me/Log4Shell-Payloads★ 8githubgithub.com/securekomodo/text4shell-poc★ 8githubgithub.com/QAInsights/cve-2022-42889-jmeter★ 7githubgithub.com/vickyaryan7/Text4shell-exploit★ 5githubgithub.com/akshayithape-devops/CVE-2022-42889-POC★ 5githubgithub.com/smileostrich/Text4Shell-Scanner★ 5githubgithub.com/0xmaximus/Apache-Commons-Text-CVE-2022-42889★ 4githubgithub.com/chainguard-dev/text4shell-policy★ 4githubgithub.com/s3l33/CVE-2022-42889★ 3githubgithub.com/stavrosgns/Text4ShellPayloads★ 3githubgithub.com/uk0/cve-2022-42889-intercept★ 3githubgithub.com/Gotcha1G/CVE-2022-42889★ 2githubgithub.com/sunnyvale-it/CVE-2022-42889-PoC★ 2githubgithub.com/devenes/text4shell-cve-2022-42889★ 2githubgithub.com/humbss/CVE-2022-42889★ 2githubgithub.com/Vulnmachines/text4shell-CVE-2022-42889★ 2githubgithub.com/Goultarde/CVE-2022-42889-text4shell★ 1githubgithub.com/tulhan/commons-text-goat★ 1githubgithub.com/gokul-ramesh/text4shell-exploit★ 1githubgithub.com/rhitikwadhvana/CVE-2022-42889-Text4Shell-Exploit-POC★ 1githubgithub.com/sangrok-jeon/CVE-2022-42889-Analysis★ 0githubgithub.com/Dima2021/cve-2022-42889-text4shell★ 0githubgithub.com/gustanini/CVE-2022-42889-Text4Shell-POC★ 0githubgithub.com/adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889★ 0githubgithub.com/galoget/CVE-2022-42889-Text4Shell-Docker★ 0githubgithub.com/engranaabubakar/CVE-2022-42889★ 0githubgithub.com/rockmelodies/CVE-2022-42889★ 0githubgithub.com/eunomie/cve-2022-42889-check★ 0githubgithub.com/Syndicate27/text4shell-exploit★ 0githubgithub.com/Sic4rio/CVE-2022-42889★ 0githubgithub.com/ReachabilityOrg/cve-2022-42889-text4shell-docker★ 0githubgithub.com/neerazz/CVE-2022-42889★ 0githubgithub.com/hotblac/text4shell★ 0githubgithub.com/necroteddy/CVE-2022-42889★ 0githubgithub.com/KosmicOwl045/ICT287-CVE-2022-42889★ 0githubgithub.com/Hkaeeeer/CVE-2022-42889★ 0githubgithub.com/34006133/CVE-2022-42889★ 0githubgithub.com/aaronm-sysdig/text4shell-docker★ 0githubgithub.com/kiralab/text4shell-scan★ 0githubgithub.com/DimaMend/cve-2022-42889-text4shell★ 0githubgithub.com/shoucheng3/asf__commons-text_CVE-2022-42889_1-9★ 0githubgithub.com/joshbnewton31080/cve-2022-42889-text4shell★ 0vulncheckvulncheck.com/xdb/5711893e4f71unverifiedvulncheckvulncheck.com/xdb/a106c45cba03unverifiedvulncheckvulncheck.com/xdb/2b3df872e90dunverifiedvulncheckvulncheck.com/xdb/a73e401bf0b9unverifiedvulncheckvulncheck.com/xdb/fec0c3608e1eunverifiedvulncheckvulncheck.com/xdb/096455128c6cunverifiedvulncheckvulncheck.com/xdb/c58be2e707deunverifiedvulncheckvulncheck.com/xdb/6d22ed98f9b3unverifiedvulncheckvulncheck.com/xdb/150dd9cbab37unverifiedvulncheckvulncheck.com/xdb/db1b1f344e82unverifiedvulncheckvulncheck.com/xdb/926c5926fe6cunverifiedvulncheckvulncheck.com/xdb/9d48c2c44fe0unverifiedvulncheckvulncheck.com/xdb/7d70e4329519unverifiedvulncheckvulncheck.com/xdb/074f3a1904d7unverifiedcve_referencepacketstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.htmlunverifiedcve_referencepacketstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/746f9b679411unverifiedvulncheckvulncheck.com/xdb/0109e0687233unverifiedvulncheckvulncheck.com/xdb/b96cd6d6920eunverifiedvulncheckvulncheck.com/xdb/f11ebcf632b8unverifiedvulncheckvulncheck.com/xdb/94c887a105d9unverifiedvulncheckvulncheck.com/xdb/be7e0fe71d54unverifiedvulncheckvulncheck.com/xdb/5c158c054bc7unverifiedvulncheckvulncheck.com/xdb/7129115e6e84unverifiedvulncheckvulncheck.com/xdb/2113b466a56aunverifiedvulncheckvulncheck.com/xdb/ec24d9df68c5unverifiedvulncheckvulncheck.com/xdb/b0bb4241ccd2unverifiedvulncheckvulncheck.com/xdb/b8b25076ed7eunverifiedvulncheckvulncheck.com/xdb/314dca672d04unverifiedvulncheckvulncheck.com/xdb/c1827ab386c2unverifiedvulncheckvulncheck.com/xdb/e10770356a6bunverifiedvulncheckvulncheck.com/xdb/47c953546f47unverifiedvulncheckvulncheck.com/xdb/7e7d2cbf38dfunverifiedvulncheckvulncheck.com/xdb/3e96c4d92251unverifiedvulncheckvulncheck.com/xdb/62c7fee2481dunverifiedvulncheckvulncheck.com/xdb/f48682e5693bunverifiedvulncheckvulncheck.com/xdb/cb76b2c83924unverifiedvulncheckvulncheck.com/xdb/eacaa89daa19unverifiedvulncheckvulncheck.com/xdb/c405fdc828c1unverifiedvulncheckvulncheck.com/xdb/61b91daa4dcfunverifiedvulncheckvulncheck.com/xdb/dc8f45ac8044unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.htmlhttp://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2023/Feb/3https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1omhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022https://security.gentoo.org/glsa/202301-05https://security.netapp.com/advisory/ntap-20221020-0004/http://www.openwall.com/lists/oss-security/2022/10/13/4http://www.openwall.com/lists/oss-security/2022/10/18/1