Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-42889— Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

Quick assessment

Affected
Apache Software Foundation Apache Commons Text
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Commons Text是美国阿帕奇(Apache)基金会的一个专注于字符串算法的库。 Apache Commons Text 1.5至1.9版本存在安全漏洞,该漏洞源于默认的Lookup实例集包括可能导致任意代码执行或与远程服务器联系的插值器,可能容易受到远程代码执行或与远程服务器的无意接触的影响。

AI Predicted 9.8 Difficulty: Trivial EPSS 99.93% · P100

Public Exploits 2

ExploitDB · 1 EDB-52261 [webapps]

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-42889

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
Source: CVE Program / CVE List V5
Vulnerability Description
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Commons Text 代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Commons Text是美国阿帕奇(Apache)基金会的一个专注于字符串算法的库。 Apache Commons Text 1.5至1.9版本存在安全漏洞,该漏洞源于默认的Lookup实例集包括可能导致任意代码执行或与远程服务器联系的插值器,可能容易受到远程代码执行或与远程服务器的无意接触的影响。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Commons Text unspecified ~ 1.9 -

II. Public POCs for CVE-2022-42889

# POC Description Source Link Shenlong Link
1 CVE-2022-42889 dockerized sample application (Apache Commons Text RCE) https://github.com/0xst4n/CVE-2022-42889 POC Details
2 Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889. https://github.com/SeanWrightSec/CVE-2022-42889-PoC POC Details
3 ClusterImagePolicy demo for cve-2022-42889 text4shell https://github.com/chainguard-dev/text4shell-policy POC Details
4 An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889. https://github.com/tulhan/commons-text-goat POC Details
5 Dockerized POC for CVE-2022-42889 Text4Shell https://github.com/karthikuj/cve-2022-42889-text4shell-docker POC Details
6 cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10. https://github.com/ClickCyber/cve-2022-42889 POC Details
7 A simple application that shows how to exploit the CVE-2022-42889 vulnerability https://github.com/korteke/CVE-2022-42889-POC POC Details
8 None https://github.com/eunomie/cve-2022-42889-check POC Details
9 Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit. https://github.com/kljunowsky/CVE-2022-42889-text4shell POC Details
10 A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889 https://github.com/securekomodo/text4shell-scan POC Details
11 None https://github.com/neerazz/CVE-2022-42889 POC Details
12 通过 jvm 启动参数 以及 jps pid进行拦截非法参数 https://github.com/uk0/cve-2022-42889-intercept POC Details
13 Proof of Concept Appliction for testing CVE-2022-42889 https://github.com/securekomodo/text4shell-poc POC Details
14 None https://github.com/humbss/CVE-2022-42889 POC Details
15 This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability https://github.com/stavrosgns/Text4ShellPayloads POC Details
16 python script for CVE-2022-42889 https://github.com/s3l33/CVE-2022-42889 POC Details
17 Dockerized PoC for CVE-2022-42889 Text4Shell https://github.com/galoget/CVE-2022-42889-Text4Shell-Docker POC Details
18 CVE-2022-42889 Text4Shell Exploit POC https://github.com/rhitikwadhvana/CVE-2022-42889-Text4Shell-Exploit-POC POC Details
19 A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability. https://github.com/akshayithape-devops/CVE-2022-42889-POC POC Details
20 Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile https://github.com/0xmaximus/Apache-Commons-Text-CVE-2022-42889 POC Details
21 Vulnerability Scanner for CVE-2022-42889 (Text4Shell) https://github.com/smileostrich/Text4Shell-Scanner POC Details
22 CVE-2022-42889 aka Text4Shell research & PoC https://github.com/cxzero/CVE-2022-42889-text4shell POC Details
23 Text4Shell PoC Exploit https://github.com/west-wind/CVE-2022-42889 POC Details
24 None https://github.com/Vulnmachines/text4shell-CVE-2022-42889 POC Details
25 CVE-2022-42889 Blind-RCE Nuclei Template https://github.com/Hack4rLIFE/CVE-2022-42889 POC Details
26 Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability) https://github.com/cryxnet/CVE-2022-42889-RCE POC Details
27 CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept https://github.com/sunnyvale-it/CVE-2022-42889-PoC POC Details
28 Script to handle CVE 2022-42889 https://github.com/QAInsights/cve-2022-42889-jmeter POC Details
29 None https://github.com/adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889 POC Details
30 Python Script to exploit RCE of CVE-2022-42889 https://github.com/pwnb0y/Text4shell-exploit POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-42889

登录查看更多情报信息。

Vendor Advisories for CVE-2022-42889 (2)

Exploits & Public PoCs for CVE-2022-42889 (2)

Mailing List Discussions for CVE-2022-42889 (3)

Other References for CVE-2022-42889 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-42889

No comments yet


Leave a comment