QID 377701
Date Published: 2022-10-27
QID 377701: Apache Commons Arbitrary Code Execution (ACE) Vulnerability (Text4Shell) (CVE-2022-42889) Scan Utility
Apache Commons Text is a popular open-source Java library with an "interpolation system" that allows developers to modify, decode, generate, and escape strings based on inputted string lookups. Apache Commons text is affected by a Arbitrary code execution Vulnerability dubbed as "Text4Shell.
Affected Versions:
Apache Commons Text Versions 1.5 through 1.9
QID Detection: (Authenticated) - Windows
This QID reads the file generated by Qualys utility Qualys Text4Shell Scan Utility for Windows
The QID reads 1st 100000 characters from the generated output file.
Successful exploitation of this vulnerability could will allow an attacker to perform Arbitrary Code Execution.
Solution
Customers are advised to visit Apache Commons Text for more information on this vulnerability.
Vendor References
- Apache Commons Text -
lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om
CVEs related to QID 377701
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-599f-7c49-w659 |
|