Feed/CVE-2022-42889
CVE-2022-42889CRITICALCVSS 9.8

CVE-2022-42889

Published Oct 13, 2022·Updated Jun 16, 2026

NVD Description

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

Public Exploits & PoCs48 found

PoC: cve-2022-42889-text4shell-docker

Dockerized POC for CVE-2022-42889 Text4Shell

5

PoC: CVE-2022-42889-RCE-POC

CVE-2022-42889 Remote Code Exection Vulnerability aka Text4Shell

4

PoC: cve-2022-42889-scanner

Esta herramienta te ayudará a buscar la versión apache de una página web y decirte si es vulnerable o no.

2

PoC: cve-2022-42889-intercept

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

2

PoC: text4shell-exploit

A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.

1

PoC: text4shell-cve-2022-42889

Kubernetes Lab for CVE-2022-42889

1

PoC: text4shellburpscanner

text4shell(CVE-2022-42889) BurpSuite Scanner

1

PoC: cve-2022-42889-jmeter

Script to handle CVE 2022-42889

1

PoC: CVE-2022-42889-PoC

Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)

1

PoC: CVE-2022-42889

Text4Shell PoC Exploit

1

PoC: CVE-2022-42889-POC

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

1

PoC: text4shell-scan

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

1

PoC: CVE-2022-42889

CVE-2022-42889 sample application (Apache Commons Text RCE)

1

PoC: CVE-2022-42889

exploit for CVE-2022-42889

PoC: ICT287-CVE-2022-42889

Setup and exploit recreation for CVE-2022-42889 Text4Shell.

PoC: CVE-2022-42889-Analysis

CVE-2022-42889 취약점 분석보고서

PoC: CVE-2022-42889-text4shell

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code Execution (RCE) via script interpolation to establish a reverse shell. This version is a structured optimization based on the original exploit found at Exploit-DB (ID: 52261).

PoC: text4shell-exploit

A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.

PoC: CVE-2022-42889

RCE PoC in Apache Commons Text

PoC: CVE-2022-42889

Text4Shell

PoC: CVE-2022-42889-Text4Shell-POC

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.

PoC: text4shell-docker

Dockerized POC for CVE-2022-42889 Text4Shell

PoC: CVE-2022-42889

A critical TEXT4SHELL Apache vulnerability in SonicWall interfaces may allow a remote unauthenticated attacker to execute arbitrary code and take full control of the impacted Product...

PoC: CVE-2022-42889

docker for CVE-2022-42889

PoC: text4shell

A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability

PoC: vtrade-common

https://github.com/karthikuj/cve-2022-42889-text4shell-docker.git

PoC: text4shell-exploit

CVE-2022-42889 - Text4Shell exploit

PoC: Text4shell-exploit

Python Script to exploit RCE of CVE-2022-42889

PoC: CVE-2022-42889-PoC

CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept

PoC: CVE-2022-42889

CVE-2022-42889 Blind-RCE Nuclei Template

PoC: CVE-2022-42889-text4shell

CVE-2022-42889 aka Text4Shell research & PoC

PoC: Text4Shell-Scanner

Vulnerability Scanner for CVE-2022-42889 (Text4Shell)

PoC: Apache-Commons-Text-CVE-2022-42889

Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile

PoC: CVE-2022-42889-POC_TEXT4SHELL

CVE-2022-42889-POC_TEXT4SHELL

PoC: CVE-2022-42889-Text4Shell-Exploit-POC

CVE-2022-42889 Text4Shell Exploit POC

PoC: CVE-2022-42889-Text4Shell-Docker

Dockerized PoC for CVE-2022-42889 Text4Shell

PoC: CVE-2022-42889

python script for CVE-2022-42889

PoC: Text4ShellPayloads

This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability

PoC: text4shell-poc

Proof of Concept Appliction for testing CVE-2022-42889

PoC: text4shell-scan

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

PoC: CVE-2022-42889-text4shell

Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.

PoC: CVE-2022-42889

CVE-2022-42889 dockerized sample application (Apache Commons Text RCE)

PoC: CVE-2022-42889-POC

A simple application that shows how to exploit the CVE-2022-42889 vulnerability

PoC: cve-2022-42889

cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10.

PoC: commons-text-goat

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

PoC: text4shell-policy

ClusterImagePolicy demo for cve-2022-42889 text4shell

PoC: CVE-2022-42889-PoC

Proof of Concept for CVE-2022-42889

PoC: CVE-2022-42889-MASS-RCE

Mass exploitation tool for CVE-2022-42889 (Apache Commons Text RCE) supports list of ips

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free