Sploitus

CVE-2022-42889

43 known exploits for CVE-2022-42889

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

Apache Commons Text
< 1.10.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.9% (100th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2022-10-13

Workaround

Upgrade to Apache Commons Text 1.10.0.

CVE-2022-42889 at NVD
Authoritative description, scoring and affected products

43 known exploits for CVE-2022-42889

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Code Injection in Apache Commons_Text
2026-07-15 HkaeeeerGITHUB
Docker_MCP_POC
2026-05-18 shubhamchavGITHUB
Docker_Desktop_POC
2026-04-29 shubhamchavGITHUB
Exploit for Code Injection in Apache Commons_Text
2026-03-30 KosmicOwl045GITHUB
Exploit for Code Injection in Apache Commons_Text
2026-03-16 sangrok-jeonGITHUB
Exploit for Uncontrolled Resource Consumption in Siemens 6Bk1602-0Aa12-0Tp0_Firmware
2026-03-13 lizuyi-6GITHUB
Exploit for Code Injection in Apache Commons_Text
2026-03-10 engranaabubakarGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2026-03-10 MkwayGITHUB
Exploit for Code Injection in Apache Commons_Text
2026-01-02 GoultardeGITHUB
Text4Shell-Exploit - A Custom Python-based Proof-Of-Concept (PoC) Exploit Targeting Text4Shell (CVE-2022-42889), A Critical Remote Code Execution Vulnerability In Apache Commons Text Versions < 1.10
2025-04-23 KitPloitKITPLOIT
Apache Commons Text 1.10.0 - Remote Code Execution
2025-04-18 Arjun ChaudharyEXPLOITDBPython
📄 Apache Commons Text 1.10.0 Remote Code Execution
2025-04-18 Arjun ChaudharyPACKETSTORMPython
Exploit for Code Injection in Apache Commons_Text
2025-03-24 Syndicate27GITHUB
Exploit for Code Injection in Apache Commons_Text
2024-02-08 MendDemo-joshGITHUB
Apache Commons Text 1.9 Remote Code Execution Exploit
2024-01-21 metasploitZDTRuby
Apache Commons Text 1.9 Remote Code Execution
2024-01-19 Alvaro Munoz, Karthik UJ, Gaurav Jain, metasploit.comPACKETSTORMRuby
Exploit for Code Injection in Apache Commons_Text
2023-09-09 0xxisGITHUB
Exploit for Code Injection in Apache Commons_Text
2023-09-09 34006133GITHUB
Exploit for Code Injection in Apache Commons_Text
2023-09-09 0xxqGITHUB
Exploit for Code Injection in Apache Commons_Text
2023-06-27 gustaniniGITHUB
Exploit for Code Injection in Apache Commons_Text
2023-06-27 gustaniniGITHUB
Exploit for Code Injection in Apache Commons_Text
2023-04-04 necroteddyGITHUB
Exploit for Code Injection in Apache Commons_Text
2023-02-28 devenesGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-12-07 gokul-rameshGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-11-21 pwnb0yGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-11-07 adarshpv9746GITHUB
Exploit for Code Injection in Apache Commons_Text
2022-11-05 sunnyvale-itGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-11-04 cryxnetGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-11-04 cryxnetGITHUB
Exploit for Improper Handling of Exceptional Conditions in Google Chrome
2022-10-25 numencyberGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-23 cxzeroGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-23 akshayithape-devopsGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-22 s3l33GITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-21 stavrosgnsGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-20 uk0GITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-20 securekomodoGITHUB
Exploit for Out-of-bounds Read in Bentley Microstation
2022-10-19 iamsanjayGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-19 kljunowskyGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-19 neerazzGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-18 kortekeGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-18 ClickCyberGITHUB
Exploit for Code Injection in Apache Commons_Text
2022-10-17 SeanWrightSecGITHUB
Apache Commons Text RCE
2022-10-13 Alvaro Muñoz, Karthik UJ, Gaurav JainMETASPLOITRuby