Apache Commons Text是美国阿帕奇(Apache)基金会的一个专注于字符串算法的库。 Apache Commons Text 1.5至1.9版本存在安全漏洞,该漏洞源于默认的Lookup实例集包括可能导致任意代码执行或与远程服务器联系的插值器,可能容易受到远程代码执行或与远程服务器的无意接触的影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Commons Text | unspecified ~ 1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-42889 dockerized sample application (Apache Commons Text RCE) | https://github.com/0xst4n/CVE-2022-42889 | POC Details |
| 2 | Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889. | https://github.com/SeanWrightSec/CVE-2022-42889-PoC | POC Details |
| 3 | ClusterImagePolicy demo for cve-2022-42889 text4shell | https://github.com/chainguard-dev/text4shell-policy | POC Details |
| 4 | An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889. | https://github.com/tulhan/commons-text-goat | POC Details |
| 5 | Dockerized POC for CVE-2022-42889 Text4Shell | https://github.com/karthikuj/cve-2022-42889-text4shell-docker | POC Details |
| 6 | cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10. | https://github.com/ClickCyber/cve-2022-42889 | POC Details |
| 7 | A simple application that shows how to exploit the CVE-2022-42889 vulnerability | https://github.com/korteke/CVE-2022-42889-POC | POC Details |
| 8 | None | https://github.com/eunomie/cve-2022-42889-check | POC Details |
| 9 | Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit. | https://github.com/kljunowsky/CVE-2022-42889-text4shell | POC Details |
| 10 | A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889 | https://github.com/securekomodo/text4shell-scan | POC Details |
| 11 | None | https://github.com/neerazz/CVE-2022-42889 | POC Details |
| 12 | 通过 jvm 启动参数 以及 jps pid进行拦截非法参数 | https://github.com/uk0/cve-2022-42889-intercept | POC Details |
| 13 | Proof of Concept Appliction for testing CVE-2022-42889 | https://github.com/securekomodo/text4shell-poc | POC Details |
| 14 | None | https://github.com/humbss/CVE-2022-42889 | POC Details |
| 15 | This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability | https://github.com/stavrosgns/Text4ShellPayloads | POC Details |
| 16 | python script for CVE-2022-42889 | https://github.com/s3l33/CVE-2022-42889 | POC Details |
| 17 | Dockerized PoC for CVE-2022-42889 Text4Shell | https://github.com/galoget/CVE-2022-42889-Text4Shell-Docker | POC Details |
| 18 | CVE-2022-42889 Text4Shell Exploit POC | https://github.com/rhitikwadhvana/CVE-2022-42889-Text4Shell-Exploit-POC | POC Details |
| 19 | A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability. | https://github.com/akshayithape-devops/CVE-2022-42889-POC | POC Details |
| 20 | Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile | https://github.com/0xmaximus/Apache-Commons-Text-CVE-2022-42889 | POC Details |
| 21 | Vulnerability Scanner for CVE-2022-42889 (Text4Shell) | https://github.com/smileostrich/Text4Shell-Scanner | POC Details |
| 22 | CVE-2022-42889 aka Text4Shell research & PoC | https://github.com/cxzero/CVE-2022-42889-text4shell | POC Details |
| 23 | Text4Shell PoC Exploit | https://github.com/west-wind/CVE-2022-42889 | POC Details |
| 24 | None | https://github.com/Vulnmachines/text4shell-CVE-2022-42889 | POC Details |
| 25 | CVE-2022-42889 Blind-RCE Nuclei Template | https://github.com/Hack4rLIFE/CVE-2022-42889 | POC Details |
| 26 | Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability) | https://github.com/cryxnet/CVE-2022-42889-RCE | POC Details |
| 27 | CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept | https://github.com/sunnyvale-it/CVE-2022-42889-PoC | POC Details |
| 28 | Script to handle CVE 2022-42889 | https://github.com/QAInsights/cve-2022-42889-jmeter | POC Details |
| 29 | None | https://github.com/adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889 | POC Details |
| 30 | Python Script to exploit RCE of CVE-2022-42889 | https://github.com/pwnb0y/Text4shell-exploit | POC Details |
No public POC found.
Login to generate AI POCNo comments yet