---
title: "CVE-2022-42889"
canonical: "https://kb.cynergy.app/space/MD/928219253/CVE-2022-42889"
format: markdown
---
**Description**

Specific versions of [Commons Text](https://cve.report/software/apache/commons_text) from [Apache](https://cve.report/vendor/apache) contain the following vulnerability:

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

**Published On**

10/13/2022

**Updated On**

10/21/2022

**Trending**

TRUE

**CWE**

[CWE-94](http://cwe.mitre.org/data/definitions/94.html)

**Exploit**


**Mitigation:**

![image](media://4299985b-2371-4ad8-a7f8-40ddb81b48fb)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Upgrade to Apache Commons Text 1.10.0.

- [150586](https://cve.report/qid/150586) Apache Commons Text Remote Code Execution (RCE) Vulnerability (Text4Shell) (CVE-2022-42889)
- [377639](https://cve.report/qid/377639) Apache Commons Arbitrary Code Execution (ACE) Vulnerability (Text4Shell) (CVE-2022-42889)
- [377682](https://cve.report/qid/377682) F5 BIG-IP Apache Commons Text Vulnerability (K24823443) (Text4Shell) (CVE-2022-42889)
- [377701](https://cve.report/qid/377701) Apache Commons Arbitrary Code Execution (ACE) Vulnerability (Text4Shell) (CVE-2022-42889) Scan Utility

**References**

|  |  |  |
| --- | --- | --- |
| Security Advisory | <span style="color: #ffffff">**[psirt.global.sonicwall.com](http://psirt.global.sonicwall.com)**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| oss-security - CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults | [http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| oss-security - Re: CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults | [http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| <span style="color: #ffffff">**No Description Provided**</span> | <span style="color: #ffffff">**[lists.apache.org](http://lists.apache.org)**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| CVE-2022-42889 Apache Commons Text Vulnerability in NetApp Products | NetApp Product Security | [http://security.netapp.com](http://security.netapp.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |