Apache Security Update – 16 October 2022

Apache has released a security Update to address a critical vulnerability in Apache Commons. The remote attacker could exploit this vulnerability to take control of the affected system.

Apache Commons Text is vulnerable to code execution caused by an insecure interpolation defaults flaw. The attacker could exploit this vulnerability by sending a specially-crafted input to execute arbitrary code on the system.

Apache Commons Text code execution (CVE-2022-42889):

  •  CVSS: 9.8
  •  Attack Vector: Network
  •  Attack Complexity: Low
  •  Privileges Required: None
  •  User Interaction: None
  •  Consequences: Gain Access
Vulnerabilities
  • CVE-2022-42889
Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed.
Apache Updates
Commons Apache

References