← volver
CVE-2022-42889explotación observada

Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

84Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 100%
de la publicación al arma4 días
Publicada en NVD13 oct
1ª PoC+4d
metasploit13 oct
VulnCheck+91d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
VulnCheck
93 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
4 productos (5 componentes)
Red Hat OpenShift Container Platform 3.11 · Red Hat Integration Camel K 1 · Red Hat JBoss Enterprise Application Platform 7 · Red Hat JBoss Enterprise Application Platform Expansion Pack
workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.
Corregido
18 productos (129 componentes)
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 · OpenShift Developer Tools and Services for OCP 4.12 · OpenShift Developer Tools and Services for OCP 4.13 · y otros 13
No afectado
20 productos (2385 componentes)porque el código vulnerable no está presente en el producto
Red Hat Satellite 6.13 for RHEL 8 · Red Hat OpenShift Container Platform 4.10 · Red Hat OpenShift Container Platform 4.9 · Red Hat Satellite 6.12 for RHEL 8 · OpenShift Developer Tools and Services for OCP 4.11 for RHEL 8 · y otros 15
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
PoCs públicas encontradas93
exploitdbwww.exploit-db.com/exploits/52261no verificadogithubgithub.com/karthikuj/cve-2022-42889-text4shell-docker76githubgithub.com/kljunowsky/CVE-2022-42889-text4shell57githubgithub.com/ClickCyber/cve-2022-4288939githubgithub.com/SeanWrightSec/CVE-2022-42889-PoC34githubgithub.com/cxzero/CVE-2022-42889-text4shell20githubgithub.com/f0ng/text4shellburpscanner20githubgithub.com/cryxnet/CVE-2022-42889-RCE15githubgithub.com/alealeluyah/CVE-2022-42889-Text4Shell-POC13githubgithub.com/korteke/CVE-2022-42889-POC10githubgithub.com/ifconfig-me/Log4Shell-Payloads8githubgithub.com/securekomodo/text4shell-poc8githubgithub.com/QAInsights/cve-2022-42889-jmeter7githubgithub.com/akshayithape-devops/CVE-2022-42889-POC5githubgithub.com/vickyaryan7/Text4shell-exploit5githubgithub.com/smileostrich/Text4Shell-Scanner5githubgithub.com/chainguard-dev/text4shell-policy4githubgithub.com/0xmaximus/Apache-Commons-Text-CVE-2022-428894githubgithub.com/uk0/cve-2022-42889-intercept3githubgithub.com/stavrosgns/Text4ShellPayloads3githubgithub.com/s3l33/CVE-2022-428893githubgithub.com/devenes/text4shell-cve-2022-428892githubgithub.com/Vulnmachines/text4shell-CVE-2022-428892githubgithub.com/humbss/CVE-2022-428892githubgithub.com/Gotcha1G/CVE-2022-428892githubgithub.com/sunnyvale-it/CVE-2022-42889-PoC2githubgithub.com/rhitikwadhvana/CVE-2022-42889-Text4Shell-Exploit-POC1githubgithub.com/Goultarde/CVE-2022-42889-text4shell1githubgithub.com/gokul-ramesh/text4shell-exploit1githubgithub.com/tulhan/commons-text-goat1githubgithub.com/galoget/CVE-2022-42889-Text4Shell-Docker0githubgithub.com/neerazz/CVE-2022-428890githubgithub.com/ReachabilityOrg/cve-2022-42889-text4shell-docker0githubgithub.com/Syndicate27/text4shell-exploit0githubgithub.com/engranaabubakar/CVE-2022-428890githubgithub.com/sangrok-jeon/CVE-2022-42889-Analysis0githubgithub.com/KosmicOwl045/ICT287-CVE-2022-428890githubgithub.com/kiralab/text4shell-scan0githubgithub.com/Sic4rio/CVE-2022-428890githubgithub.com/adarshpv9746/Text4shell--Automated-exploit---CVE-2022-428890githubgithub.com/joshbnewton31080/cve-2022-42889-text4shell0githubgithub.com/Hkaeeeer/CVE-2022-428890githubgithub.com/34006133/CVE-2022-428890githubgithub.com/Dima2021/cve-2022-42889-text4shell0githubgithub.com/rockmelodies/CVE-2022-428890githubgithub.com/eunomie/cve-2022-42889-check0githubgithub.com/hotblac/text4shell0githubgithub.com/necroteddy/CVE-2022-428890githubgithub.com/gustanini/CVE-2022-42889-Text4Shell-POC0githubgithub.com/aaronm-sysdig/text4shell-docker0githubgithub.com/DimaMend/cve-2022-42889-text4shell0githubgithub.com/shoucheng3/asf__commons-text_CVE-2022-42889_1-90vulncheckvulncheck.com/xdb/62c7fee2481dno verificadovulncheckvulncheck.com/xdb/f48682e5693bno verificadovulncheckvulncheck.com/xdb/cb76b2c83924no verificadovulncheckvulncheck.com/xdb/eacaa89daa19no verificadovulncheckvulncheck.com/xdb/c405fdc828c1no verificadovulncheckvulncheck.com/xdb/61b91daa4dcfno verificadovulncheckvulncheck.com/xdb/dc8f45ac8044no verificadovulncheckvulncheck.com/xdb/5711893e4f71no verificadovulncheckvulncheck.com/xdb/a106c45cba03no verificadovulncheckvulncheck.com/xdb/2b3df872e90dno verificadovulncheckvulncheck.com/xdb/a73e401bf0b9no verificadovulncheckvulncheck.com/xdb/fec0c3608e1eno verificadovulncheckvulncheck.com/xdb/096455128c6cno verificadovulncheckvulncheck.com/xdb/c58be2e707deno verificadovulncheckvulncheck.com/xdb/6d22ed98f9b3no verificadovulncheckvulncheck.com/xdb/150dd9cbab37no verificadovulncheckvulncheck.com/xdb/db1b1f344e82no verificadovulncheckvulncheck.com/xdb/926c5926fe6cno verificadovulncheckvulncheck.com/xdb/f11ebcf632b8no verificadovulncheckvulncheck.com/xdb/9d48c2c44fe0no verificadovulncheckvulncheck.com/xdb/7d70e4329519no verificadovulncheckvulncheck.com/xdb/074f3a1904d7no verificadovulncheckvulncheck.com/xdb/b96cd6d6920eno verificadocve_referencepacketstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.htmlno verificadocve_referencepacketstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.htmlno verificadovulncheckvulncheck.com/xdb/2113b466a56ano verificadovulncheckvulncheck.com/xdb/0109e0687233no verificadovulncheckvulncheck.com/xdb/94c887a105d9no verificadovulncheckvulncheck.com/xdb/7129115e6e84no verificadovulncheckvulncheck.com/xdb/5c158c054bc7no verificadovulncheckvulncheck.com/xdb/be7e0fe71d54no verificadovulncheckvulncheck.com/xdb/746f9b679411no verificadovulncheckvulncheck.com/xdb/ec24d9df68c5no verificadovulncheckvulncheck.com/xdb/b0bb4241ccd2no verificadovulncheckvulncheck.com/xdb/b8b25076ed7eno verificadovulncheckvulncheck.com/xdb/314dca672d04no verificadovulncheckvulncheck.com/xdb/c1827ab386c2no verificadovulncheckvulncheck.com/xdb/e10770356a6bno verificadovulncheckvulncheck.com/xdb/47c953546f47no verificadovulncheckvulncheck.com/xdb/7e7d2cbf38dfno verificadovulncheckvulncheck.com/xdb/3e96c4d92251no verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.