QID 377701

Date Published: 2022-10-27

QID 377701: Apache Commons Arbitrary Code Execution (ACE) Vulnerability (Text4Shell) (CVE-2022-42889) Scan Utility

Apache Commons Text is a popular open-source Java library with an "interpolation system" that allows developers to modify, decode, generate, and escape strings based on inputted string lookups. Apache Commons text is affected by a Arbitrary code execution Vulnerability dubbed as "Text4Shell.

Affected Versions:
Apache Commons Text Versions 1.5 through 1.9

QID Detection: (Authenticated) - Windows
This QID reads the file generated by Qualys utility Qualys Text4Shell Scan Utility for Windows
The QID reads 1st 100000 characters from the generated output file.

Successful exploitation of this vulnerability could will allow an attacker to perform Arbitrary Code Execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to visit Apache Commons Text for more information on this vulnerability.
    Vendor References

    CVEs related to QID 377701

    Software Advisories
    Advisory ID Software Component Link
    GHSA-599f-7c49-w659 URL Logo github.com/advisories/GHSA-599f-7c49-w659