Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-42889: Apache Commons Text library may run unwanted code
CVE-2022-42889 · published 3 days ago
Summary
The Apache Commons Text component used in several applications, including Apache Commons Text itself, Guicedee services, NetApp BlueXP, and Juniper Security Threat Response Manager, can be tricked into executing code it shouldn't. This could let an attacker run malicious actions on your system. Update to the latest patched version of the library as soon as possible to protect your environment.
What to do
- Update apache org.apache.commons:commons-text to version 1.10.0.
- Update org.apache.commons:commons-text to version 1.9-aikido.1.
- Update io.root.org.apache.commons:commons-text to version 1.9-root.io.1.
- Update apache commons_text to version 1.10.0 or later.
- Update juniper security_threat_response_manager to version 7.5.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | apache | org.apache.commons:commons-text |
>= 1.5, < 1.10.0 Fix: upgrade to 1.10.0
|
| maven | guicedee | com.guicedee.services:commons-text | <= 1.2.2.1-jre17 |
| – | apache | commons_text |
>= 1.5, < 1.10.0 cpe:2.3:a:apache:commons_text:*:*:*:*:*:*:*:* |
| – | netapp | bluexp |
All versions
cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* |
| – | juniper | security_threat_response_manager |
< 7.5.0 7.5.0 cpe:2.3:a:juniper:security_threat_response_manager:*:*:*:*:*:*:*:* |
| Root:Maven | – | org.apache.commons:commons-text |
< 1.9-aikido.1 Fix: upgrade to 1.9-aikido.1
|
| Root:Maven | – | io.root.org.apache.commons:commons-text |
< 1.9-root.io.1 Fix: upgrade to 1.9-root.io.1
|
Original advisory text
CVE-2022-42889 in org.apache.commons:commons-text - Patched by Root
Root has patched CVE-2022-42889 in the org.apache.commons:commons-text package for Root:Maven. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-42889
- https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om
- http://www.openwall.com/lists/oss-security/2022/10/13/4
- https://securitylab.github.com/advisories/GHSL-2022-018_Apache_Commons_Text
- http://www.openwall.com/lists/oss-security/2022/10/18/1
- https://security.netapp.com/advisory/ntap-20221020-0004/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022
- https://security.gentoo.org/glsa/202301-05
- http://seclists.org/fulldisclosure/2023/Feb/3
- http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Se...
- https://arxiv.org/pdf/2306.05534
- http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-...
- https://github.com/advisories/GHSA-599f-7c49-w659
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 100%
Type
CWE-94Code Injection
Timeline
Published22 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta