
=====================================================================

                               CERT-Renater

                    Note d'Information No. 2022/VULN384

_____________________________________________________________________

DATE                : 14/10/2022

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Commons Text versions
                                 prior to 1.10.0.

=====================================================================
https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om
_____________________________________________________________________


CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when
applied to untrusted input due to insecure interpolation defaults
Severity: important


Description:

Apache Commons Text performs variable interpolation, allowing
properties to be dynamically evaluated and expanded. The standard
format for interpolation is "${prefix:name}", where "prefix" is
used to locate an instance of
org.apache.commons.text.lookup.StringLookup that performs the
interpolation. Starting with version 1.5 and continuing through
1.9, the set of default Lookup instances included interpolators
that could result in arbitrary code execution or contact with
remote servers. These lookups are: - "script" - execute
expressions using the JVM script execution engine (javax.script)
- "dns" - resolve dns records - "url" - load values from urls,
including from remote servers Applications using the interpolation
defaults in the affected versions may be vulnerable to remote
code execution or unintentional contact with remote servers if
untrusted configuration values are used. Users are recommended
to upgrade to Apache Commons Text 1.10.0, which disables the
problematic interpolators by default.


Mitigation:

Upgrade to Apache Commons Text 1.10.0.

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================


