Company
Date Published
Author
Ian McCloy, Director Product Management
Word count
275
Language
English
Hacker News points
None

Summary

The Text4Shell vulnerability is a critical severity security issue affecting the Apache Commons Text library, which can be exploited by an attacker if an application uses the StringSubstitutor class with variable interpolation and is using a vulnerable version of the library. The vulnerability affects Couchbase Server Enterprise Edition versions 6.0.0 and later when running the Couchbase Analytics service, as well as the Couchbase Elasticsearch Connector versions prior to 4.3.9. However, both Couchbase Server and the Couchbase Elasticsearch Connectors are not impacted by this vulnerability due to not using dynamic variable interpolation capabilities of Apache Commons Text. The Couchbase Server Community Edition is also not affected by this issue. A patched version of the library has been included in Couchbase Server version 7.1.3, and updated versions of the Elasticsearch connector have been released as well.