{"schema_version":"1.7.3","id":"GHSA-599f-7c49-w659","published":"2022-10-13T19:00:17Z","modified":"2024-02-16T08:09:06.872889Z","aliases":["CVE-2022-42889"],"summary":"Arbitrary code execution in Apache Commons Text","details":"Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is \"${prefix:name}\", where \"prefix\" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - \"script\" - execute expressions using the JVM script execution engine (javax.script) - \"dns\" - resolve dns records - \"url\" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.","affected":[{"package":{"name":"org.apache.commons:commons-text","ecosystem":"Maven","purl":"pkg:maven/org.apache.commons/commons-text"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5"},{"fixed":"1.10.0"}]}],"versions":["1.5","1.6","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-599f-7c49-w659/GHSA-599f-7c49-w659.json"}},{"package":{"name":"com.guicedee.services:commons-text","ecosystem":"Maven","purl":"pkg:maven/com.guicedee.services/commons-text"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.2.2.1-jre17"}]}],"versions":["0.70.0.1","0.70.0.1-rc1","0.70.0.1-rc13","0.70.0.1-rc14","0.70.0.1-rc15","0.70.0.1-rc2","0.70.0.1-rc3","0.70.0.1-rc4","0.70.0.1-rc5","0.70.0.2","0.70.0.3","0.70.0.4","0.70.0.5","0.70.0.6","0.70.0.7","1.0.0.0","1.0.1.0","1.0.1.0-jre12","1.0.1.0-jre13","1.0.1.0-jre8","1.0.1.1","1.0.1.1-jre12","1.0.1.1-jre13","1.0.1.1-jre8","1.0.1.2","1.0.1.3","1.0.1.3-jre12","1.0.1.3-jre13","1.0.1.3-jre8","1.0.1.4","1.0.1.4-jre12","1.0.1.4-jre13","1.0.1.4-jre8","1.0.1.5","1.0.1.5-jre12","1.0.1.5-jre13","1.0.1.5-jre8","1.0.1.6","1.0.1.6-jre12","1.0.1.6-jre13","1.0.1.7","1.0.1.7-jre12","1.0.1.7-jre13","1.0.1.7-jre8","1.0.10.0","1.0.10.0-jre13","1.0.10.0-jre14","1.0.10.1","1.0.10.1-jre14","1.0.10.3","1.0.10.3-jre14","1.0.10.4","1.0.10.4-jre12","1.0.10.4-jre13","1.0.10.4-jre14","1.0.11.0-jre14","1.0.11.2-jre14","1.0.11.5","1.0.11.5-jre12","1.0.11.5-jre14","1.0.11.6-jre14","1.0.11.7","1.0.11.7-jre12","1.0.11.7-jre14","1.0.12.0","1.0.12.0-jre12","1.0.12.0-jre13","1.0.12.0-jre14","1.0.12.0-jre8","1.0.12.1","1.0.12.1-jre12","1.0.12.1-jre14","1.0.12.2","1.0.12.2-jre12","1.0.12.2-jre14","1.0.12.3","1.0.12.3-jre12","1.0.12.3-jre13","1.0.12.3-jre14","1.0.12.4","1.0.12.4-jre12","1.0.12.4-jre13","1.0.12.4-jre14","1.0.12.4-jre8","1.0.12.5","1.0.12.5-jre14","1.0.13.0","1.0.13.0-jre12","1.0.13.0-jre13","1.0.13.0-jre14","1.0.13.0-jre8","1.0.13.1","1.0.13.1-jre13","1.0.13.1-jre14","1.0.13.1-jre8","1.0.13.2","1.0.13.2-jre12","1.0.13.2-jre13","1.0.13.2-jre14","1.0.13.2-jre8","1.0.13.3","1.0.13.3-jre14","1.0.13.4","1.0.13.4-jre12","1.0.13.4-jre13","1.0.13.4-jre14","1.0.13.5","1.0.13.5-jre12","1.0.13.5-jre14","1.0.13.5-jre8","1.0.14.0-RC1-jre14","1.0.14.0-RC1-jre8","1.0.14.1","1.0.14.1-jre12","1.0.14.1-jre13","1.0.14.1-jre14","1.0.14.1-jre8","1.0.14.3-jre8","1.0.14.4-jre14","1.0.14.4-jre8","1.0.15.1","1.0.15.1-jre12","1.0.15.1-jre13","1.0.15.1-jre14","1.0.15.1-jre8","1.0.15.2","1.0.15.2-jre12","1.0.15.2-jre14","1.0.15.2-jre8","1.0.15.3-jre14","1.0.15.3-jre8","1.0.15.4","1.0.15.4-jre14","1.0.15.4-jre8","1.0.15.5","1.0.15.5-jre14","1.0.15.5-jre8","1.0.16.0","1.0.16.0-jre14","1.0.16.0-jre8","1.0.17.0","1.0.17.0-jre14","1.0.17.1","1.0.17.1-jre14","1.0.17.1-jre8","1.0.18.0","1.0.18.0-jre14","1.0.18.0-jre15","1.0.18.0-jre8","1.0.18.1","1.0.18.1-jre14","1.0.18.1-jre15","1.0.18.1-jre8","1.0.19.0","1.0.19.0-jre14","1.0.19.0-jre15","1.0.19.1","1.0.19.1-jre12","1.0.19.1-jre13","1.0.19.1-jre14","1.0.19.1-jre15","1.0.19.1-jre8","1.0.19.10","1.0.19.10-jre12","1.0.19.10-jre14","1.0.19.10-jre15","1.0.19.10-jre8","1.0.19.11","1.0.19.11-jre14","1.0.19.11-jre8","1.0.19.12-jre14","1.0.19.12-jre8","1.0.19.13","1.0.19.13-jre14","1.0.19.13-jre15","1.0.19.13-jre8","1.0.19.2","1.0.19.2-jre13","1.0.19.2-jre14","1.0.19.2-jre15","1.0.19.2-jre8","1.0.19.3","1.0.19.3-jre13","1.0.19.3-jre14","1.0.19.3-jre15","1.0.19.3-jre8","1.0.19.4","1.0.19.4-jre14","1.0.19.4-jre15","1.0.19.4-jre8","1.0.19.5","1.0.19.5-jre14","1.0.19.5-jre15","1.0.19.5-jre8","1.0.19.6","1.0.19.6-jre14","1.0.19.6-jre8","1.0.19.7-jre14","1.0.19.7-jre8","1.0.19.8-jre8","1.0.19.9","1.0.19.9-jre13","1.0.19.9-jre14","1.0.19.9-jre15","1.0.19.9-jre8","1.0.2.0","1.0.2.0-jre12","1.0.2.0-jre13","1.0.2.0-jre8","1.0.2.1","1.0.2.1-jre12","1.0.2.1-jre13","1.0.2.10","1.0.2.10-jre12","1.0.2.10-jre13","1.0.2.11","1.0.2.11-jre13","1.0.2.12","1.0.2.12-jre13","1.0.2.13","1.0.2.13-jre13","1.0.2.14","1.0.2.14-jre13","1.0.2.15","1.0.2.15-jre13","1.0.2.16-jre13","1.0.2.17-jre13","1.0.2.18","1.0.2.18-jre12","1.0.2.18-jre13","1.0.2.2","1.0.2.2-jre12","1.0.2.2-jre13","1.0.2.2-jre8","1.0.2.3","1.0.2.3-jre12","1.0.2.3-jre13","1.0.2.3-jre8","1.0.2.4","1.0.2.4-jre12","1.0.2.4-jre13","1.0.2.6-jre13","1.0.2.7-jre12","1.0.2.7-jre13","1.0.2.8","1.0.2.8-jre12","1.0.2.8-jre13","1.0.2.9-jre12","1.0.2.9-jre13","1.0.20.0","1.0.20.0-jre14","1.0.20.0-jre15","1.0.20.0-jre8","1.0.20.1","1.0.20.1-jre14","1.0.20.1-jre15","1.0.20.1-jre8","1.0.20.2","1.0.20.2-jre14","1.0.20.2-jre15","1.0.20.2-jre8","1.0.3.1-jre13","1.0.3.2","1.0.3.2-jre13","1.0.3.3","1.0.3.3-jre12","1.0.3.3-jre13","1.0.4.1-jre13","1.0.4.2","1.0.4.2-jre13","1.0.4.3-jre13","1.0.4.4","1.0.4.4-jre13","1.0.5.0","1.0.5.0-jre13","1.0.5.1","1.0.5.1-jre12","1.0.5.1-jre13","1.0.5.2","1.0.5.2-jre12","1.0.5.2-jre13","1.0.5.3","1.0.5.3-jre12","1.0.5.3-jre13","1.0.5.4-jre13","1.0.5.4-jre14","1.0.5.5","1.0.5.5-jre12","1.0.5.5-jre13","1.0.5.5-jre14","1.0.6.1","1.0.6.1-jre12","1.0.6.1-jre13","1.0.6.1-jre14","1.0.6.2","1.0.6.2-jre12","1.0.6.2-jre13","1.0.6.2-jre14","1.0.6.3","1.0.6.3-jre12","1.0.6.3-jre13","1.0.6.3-jre14","1.0.6.4-jre14","1.0.6.5","1.0.6.5-jre12","1.0.6.5-jre13","1.0.6.5-jre14","1.0.6.7","1.0.6.7-jre14","1.0.7.0","1.0.7.0-jre12","1.0.7.0-jre13","1.0.7.0-jre14","1.0.7.1","1.0.7.1-jre13","1.0.7.1-jre14","1.0.7.10","1.0.7.10-jre13","1.0.7.10-jre14","1.0.7.11","1.0.7.11-jre14","1.0.7.12","1.0.7.12-jre12","1.0.7.12-jre13","1.0.7.12-jre14","1.0.7.2-jre14","1.0.7.3","1.0.7.3-jre13","1.0.7.3-jre14","1.0.7.4","1.0.7.4-jre14","1.0.7.5","1.0.7.5-jre14","1.0.7.6","1.0.7.6-jre14","1.0.7.9","1.0.7.9-jre14","1.0.8.1","1.0.8.1-jre14","1.0.8.12","1.0.8.12-jre12","1.0.8.12-jre14","1.0.8.16","1.0.8.16-jre14","1.0.8.18","1.0.8.18-jre14","1.0.8.2","1.0.8.2-jre13","1.0.8.2-jre14","1.0.8.3","1.0.8.3-jre13","1.0.8.3-jre14","1.0.8.4","1.0.8.4-jre12","1.0.8.4-jre13","1.0.8.4-jre14","1.0.8.5","1.0.8.5-jre12","1.0.8.5-jre13","1.0.8.5-jre14","1.0.8.6-jre14","1.0.9.0","1.0.9.0-jre14","1.0.9.1","1.0.9.1-jre14","1.0.9.10","1.0.9.10-jre14","1.0.9.11","1.0.9.11-jre14","1.0.9.13","1.0.9.13-jre14","1.0.9.14","1.0.9.14-jre14","1.0.9.2","1.0.9.2-jre14","1.0.9.3-jre14","1.0.9.4-jre14","1.0.9.5-jre14","1.0.9.7-jre14","1.1.0.0-jre15","1.1.0.1","1.1.0.1-jre14","1.1.0.1-jre15","1.1.0.2","1.1.0.2-jre14","1.1.0.2-jre15","1.1.0.3","1.1.0.3-jre14","1.1.0.3-jre15","1.1.0.3-jre8","1.1.0.4-jre14","1.1.0.4-jre15","1.1.0.4-jre8","1.1.0.5-jre14","1.1.0.5-jre15","1.1.0.6","1.1.0.6-jre14","1.1.0.6-jre15","1.1.0.7","1.1.0.7-jre14","1.1.0.7-jre15","1.1.0.7-jre8","1.1.0.8-SNAPSHOT-jre14","1.1.1.0","1.1.1.0-SNAPSHOT-jre14","1.1.1.0-SNAPSHOT-jre15","1.1.1.0-SNAPSHOT-jre8","1.1.1.0-jre14","1.1.1.0-jre15","1.1.1.0-jre8","1.1.1.1-SP1","1.1.1.1-jre14-SP1","1.1.1.1-jre15-SP1","1.1.1.2","1.1.1.2-jre14","1.1.1.2-jre15","1.1.1.3","1.1.1.3-jre14","1.1.1.3-jre15","1.1.1.3-jre16","1.1.1.3-jre8","1.1.1.4","1.1.1.4-jre14","1.1.1.4-jre15","1.1.1.4-jre16","1.1.1.4-jre8","1.1.1.5-jre15","1.1.1.7","1.1.1.7-jre15","1.1.1.7-jre16","1.1.1.7-jre8","1.1.1.8-jre15","1.1.1.8-jre16","1.1.1.9-jre15","1.1.1.9-jre16","1.2.0.0-jre16","1.2.0.1-jre11","1.2.0.1-jre15","1.2.0.1-jre16","1.2.0.2-jre16","1.2.0.3-jre17-rc1","1.2.1.1-jre17","1.2.1.2-jre17","1.2.2.1","1.2.2.1-jre17"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-599f-7c49-w659/GHSA-599f-7c49-w659.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42889"},{"type":"WEB","url":"https://arxiv.org/pdf/2306.05534"},{"type":"PACKAGE","url":"https://github.com/apache/commons-text"},{"type":"WEB","url":"https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om"},{"type":"WEB","url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202301-05"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20221020-0004"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2022-018_Apache_Commons_Text"},{"type":"WEB","url":"http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Feb/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/10/13/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/10/18/1"}],"database_specific":{"cwe_ids":["CWE-94"],"github_reviewed":true,"github_reviewed_at":"2022-10-13T20:22:17Z","nvd_published_at":"2022-10-13T13:15:00Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}