Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Reviewing CVE-2022-42889: The arbitrary code execution vulnerability in Apache Commons Text

Blog post from Snyk

Post Details
Company
Date Published
Author
Brian Vermeer
Word Count
437
Company Posts That Month
36
Language
English
Hacker News Points
-
Post removed?
No
Summary

CVE-2022-42889 is a high-severity remote code execution vulnerability affecting Apache Commons Text versions 1.5.x through 1.9.x, caused by variable interpolation capabilities in StringLookup that can resolve DNS records, load URLs, or execute scripts from potentially untrusted input. While comparable in principle to earlier lookup-related vulnerabilities such as Log4Shell and CVE-2022-33980, it is considered less severe and harder to exploit because script execution depends on an available JVM scripting engine. Older Java environments, particularly Java 8, may be more exposed, whereas Java 15 and later no longer include Nashorn by default and Java 17 does not provide default JavaScript or Nashorn engines. Upgrading to Apache Commons Text 1.10 or later mitigates the issue by disabling URL, DNS, and script lookup prefixes by default, and dependency scanning tools can help identify vulnerable direct or transitive library usage.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.