# CVE-2022-42889: Apache Commons Text variable interpolation code execution

**URL:** <https://ecm.community/t/cve-2022-42889-apache-commons-text-variable-interpolation-code-execution/316>\
**Category:** Java/Talend\
**Tags:** news\
**Created:** [17. Oktober 2022 um 12:22 UTC](https://ecm.community/t/cve-2022-42889-apache-commons-text-variable-interpolation-code-execution/316 "2022-10-17T12:22:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rk](https://ecm.community/user_avatar/ecm.community/rk/32/679_2.png) [@rk](https://ecm.community/u/rk)\
**Post date:** [17. Oktober 2022 um 12:22 UTC](https://ecm.community/t/cve-2022-42889-apache-commons-text-variable-interpolation-code-execution/316/1 "2022-10-17T12:22:44Z")

</div>

Auf den ersten Blick nicht mit [CVE-2021-44228: log4j JNDI Attack](https://ecm.community/t/cve-2021-44228-log4j-jndi-attack/202) vergleichbar, gibt es es eine vorläufige Warnung der NIST vor einem möglichen (Remote) Code execution bei Textinterpolation mit [Apache Commons Text](https://commons.apache.org/proper/commons-text/):

> Apache Commons Text führt eine Variableninterpolation durch, wodurch Eigenschaften dynamisch ausgewertet und erweitert werden können. Das Standardformat für die Interpolation ist „${prefix:name}“, wobei „prefix“ verwendet wird, um eine Instanz von org.apache.commons.text.lookup.StringLookup zu finden, die die Interpolation durchführt. Beginnend mit Version 1.5 und weiterführend bis 1.9 enthielt der Satz von Standard-Lookup-Instanzen Interpolatoren, die zur Ausführung von beliebigem Code oder zum Kontakt mit entfernten Servern führen konnten.

#### CVE-Eintrag

> **[NVD - CVE-2022-42889](https://nvd.nist.gov/vuln/detail/CVE-2022-42889)**

#### Hacker News

> **[Java Apache Commons Text vulnerability](https://news.ycombinator.com/item?id=33230603)**
>
> 112 points —
> 37 comments —
> daitangio —
> 7:12 AM - 17 Oct 2022

---

<div class="post-metadata">

**Author:** ![rk](https://ecm.community/user_avatar/ecm.community/rk/32/679_2.png) [@rk](https://ecm.community/u/rk)\
**Post date:** [17. Oktober 2022 um 12:25 UTC](https://ecm.community/t/cve-2022-42889-apache-commons-text-variable-interpolation-code-execution/316/2 "2022-10-17T12:25:22Z")

</div>

[https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om](https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om)

> Mitigation:
> 
> Upgrade to Apache Commons Text 1.10.0.
