VDB
BDU%3A2022-06275
BDU%3A2022-06275
PUBLISHED
CVSS 10 CRITICAL
Уязвимость компонента StringSubstitutor библиотеки Apache Common Text, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Novell Inc., Red Hat Inc., Apache Software Foundation | Debian GNU/Linux, openSUSE Tumbleweed, OpenShift Container Platform, Red Hat Integration Camel K, Red Hat Integration Camel Quarkus, Red Hat Satellite, Commons Text, OpenShift Developer Tools and Services, Red Hat Integration Camel for Spring Boot |
Timeline
- Oct 18, 2022 CVE Published
- May 11, 2023 CVE Updated
- Mar 28, 2026 PoC Published
References
- https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om url
- https://www.rapid7.com/blog/post/2022/10/17/cve-2022-42889-keep-calm-and-stop-saying-4shell/ url
- https://research.nccgroup.com/2022/10/06/technical-advisory-openjdk-weak-parsing-logic-in-java-net-inetaddress-and-related-classes/ url
- https://www.suse.com/security/cve/CVE-2022-42889.html url
- https://security-tracker.debian.org/tracker/CVE-2022-42889 advisory
- https://access.redhat.com/security/cve/cve-2022-42889 advisory