CVE-2022-42889

CRITICALNVD 9.89.8
EchelonGraph scoreLOW confidence

This critical-severity CVE scores 9.8 under NVD CVSS v3. EPSS exploit probability: 100% (99th percentile of EPSS-scored CVEs). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: epss, nvd
Weaponized
9.8EG
EchelonGraph verdictPatch this weekExploitation is likely or a public exploit exists.
  • High exploitation likelihood — EPSS 100%
  • Public exploit code is available (Metasploit, epss top5pct, epss high, public exploit)
CISA-KEV: Not listedEPSS PROB: 100%CVSS: 9.8Exploit: Metasploit · epss top5pct · epss high · public exploitExposed services: Not assessed

A fix is available — apply it.

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

CVSS v3
9.8
EG Score
9.8CRITICALlow confidence
EG Risk
99
EG Risk 99/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity98% × 45%
Exploitation100% × 40%
Automatability100% × 15%
CISA SSVC: Track at low or medium mission impact; Attend at high (mission-essential systems).
Action: A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
EPSS PROB
100%
EPSS %ILE
99th
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).

A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.

Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

October 13, 2022

Last Modified

November 21, 2024

Advisory Details (9)

Auto-updated Oct 10, 2026
Patch available.
generic

Apache Commons Text: Arbitrary Code Execution (GLSA 202301-05) — Gentoo security

https://security.gentoo.org/glsa/202301-05
generic

oss-security - Re: CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

http://www.openwall.com/lists/oss-security/2022/10/18/1
generic

oss-security - CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

http://www.openwall.com/lists/oss-security/2022/10/13/4
generic

Full Disclosure: OXAS-ADV-2022-0002: OX App Suite Security Advisory

http://seclists.org/fulldisclosure/2023/Feb/3

Patch Availability(20)

Vendor / EcosystemFix (by version range) / PatchReleasedSource
redhateap7-wildfly-0:7.1.9-2.GA_redhat_00002.1.ep7.el72025-02-24redhat
redhateap7-wildfly-0:7.3.12-3.GA_redhat_00002.1.el7eap2025-02-24redhat
redhatpatch2024-05-30redhat
redhatjenkins-2-plugins-0:4.11.1706516946-1.el82024-02-12redhat
redhatjenkins-2-plugins-0:4.14.1706516441-1.el82024-02-12redhat
redhatjenkins-2-plugins-0:4.13.1706516346-1.el82024-02-12redhat
redhatjenkins-2-plugins-0:4.12.1706515741-1.el82024-02-12redhat
redhatjenkins-2-plugins-0:4.14.1699356715-1.el82023-11-16redhat
redhatjenkins-2-plugins-0:4.13.1698292274-1.el82023-10-30redhat
redhatjenkins-2-plugins-0:4.11.1698299029-1.el82023-10-30redhat
redhatjenkins-2-plugins-0:4.12.1698294000-1.el82023-10-30redhat
redhatjenkins-2-plugins-0:4.13.1684911916-1.el82023-05-24redhat
redhatjenkins-2-plugins-0:4.12.1683009955-1.el82023-05-18redhat
redhatjenkins-2-plugins-0:4.11.1683009941-1.el82023-05-17redhat
redhatcommons-text2023-05-04redhat
redhatcandlepin-0:4.2.13-1.el8sat2023-05-03redhat
redhatjenkins-2-plugins-0:4.10.1680703106-1.el82023-04-12redhat
redhatjenkins-2-plugins-0:4.9.1680069756-1.el82023-04-05redhat
redhatpatch2023-03-08redhat
redhatcandlepin-0:4.1.18-1.el8sat2023-01-18redhat

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Affected Packages

(6 across 5 ecosystems)
Maven(2)
PackageVulnerable rangeFix by version rangeDependents
com.guicedee.services:commons-text0.70.0.1 ... 1.2.2.1-jre17 (445 versions)
  • every version through 1.2.2.1-jre17: no fix on record
—
org.apache.commons:commons-text1.5, 1.6, 1.7, 1.8, 1.9
  • 1.5 up to 1.10.0: fixed in 1.10.0
—
Debian:11(1)
PackageVulnerable rangeFix by version rangeDependents
commons-text1.10.0-1 ... 1.9-2 (10 versions)
  • every version on: no fix on record
—
Debian:12(1)
PackageVulnerable rangeFix by version rangeDependents
commons-text—
  • every version up to 1.10.0-1: fixed in 1.10.0-1
—
Debian:13(1)
PackageVulnerable rangeFix by version rangeDependents
commons-text—
  • every version up to 1.10.0-1: fixed in 1.10.0-1
—
Debian:14(1)
PackageVulnerable rangeFix by version rangeDependents
commons-text—
  • every version up to 1.10.0-1: fixed in 1.10.0-1
—

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Additional Vendor Advisories

(5)

Data Freshness Timeline

(refreshed 1× in last 7d / 3× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-04 23:19 UTCEPSS rescore
  2. 2026-09-30 16:07 UTCEG score recompute
  3. 2026-09-24 07:56 UTCOSV refresh
  4. 2026-09-07 15:58 UTCEPSS rescore
  5. 2026-09-05 01:48 UTCOSV refresh
  6. 2026-08-24 14:13 UTCEPSS rescore
  7. 2026-08-18 13:01 UTCOSV refresh
  8. 2026-08-13 21:58 UTCEPSS rescore
  9. 2026-08-13 21:58 UTCEPSS rescore
  10. 2026-08-11 13:39 UTCEPSS rescore
  11. 2026-08-06 13:44 UTCEPSS rescore
  12. 2026-08-03 08:27 UTCOSV refresh
  13. 2026-07-30 01:28 UTCEPSS rescore
  14. 2026-07-28 15:34 UTCEPSS rescore
  15. 2026-07-23 02:14 UTCEG score recompute
  16. 2026-07-22 23:02 UTCEG score recompute
  17. 2026-07-16 17:53 UTCOSV refresh
  18. 2026-07-05 02:28 UTCEPSS rescore
  19. 2026-06-28 16:32 UTCOSV refresh
  20. 2026-06-15 17:46 UTCEPSS rescore
  21. 2026-06-11 06:39 UTCOSV refresh
  22. 2026-06-01 13:50 UTCEPSS rescore
  23. 2026-06-01 13:50 UTCEPSS rescore
  24. 2026-05-27 13:39 UTCEPSS rescore
  25. 2026-05-27 13:39 UTCEPSS rescore
Show 3 more
  1. 2026-05-25 13:53 UTCEG score recompute
  2. 2026-05-25 13:53 UTCVendor advisory
  3. 2026-05-24 00:22 UTCOSV refresh

Publicly available exploits

(10 references)

Working exploit code is in the public domain (1 Metasploit module) (8 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.

  • Metasploitexploit/multi/http/apache_commons_text4shell✓ verified
    First seen Oct 13, 2022

    Apache Commons Text RCE

    Open source ↗
  • GitHub PoCifconfig-me/Log4Shell-Payloads
    First seen Jul 23, 2025

    Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

    Open source ↗
  • Exploit-DBEDB-52261
    First seen Apr 18, 2025

    Apache Commons Text 1.10.0 - Remote Code Execution

    Open source ↗
  • GitHub PoCalealeluyah/CVE-2022-42889-Text4Shell-POC
    First seen Jun 27, 2023

    This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.

    Open source ↗
  • GitHub PoCf0ng/text4shellburpscanner
    First seen Dec 9, 2022

    text4shell(CVE-2022-42889) BurpSuite Scanner

    Open source ↗
  • GitHub PoCcryxnet/CVE-2022-42889-RCE
    First seen Nov 4, 2022

    Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)

    Open source ↗
  • GitHub PoCcxzero/CVE-2022-42889-text4shell
    First seen Oct 23, 2022

    CVE-2022-42889 aka Text4Shell research & PoC

    Open source ↗
  • GitHub PoCsecurekomodo/text4shell-poc
    First seen Oct 20, 2022

    Proof of Concept Appliction for testing CVE-2022-42889

    Open source ↗
  • GitHub PoCkljunowsky/CVE-2022-42889-text4shell
    First seen Oct 19, 2022

    Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.

    Open source ↗
  • GitHub PoCClickCyber/cve-2022-42889
    First seen Oct 18, 2022

    cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10.

    Open source ↗

Frequently asked(5)

What is CVE-2022-42889?
CVE-2022-42889 is a critical vulnerability published on October 13, 2022. Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation.…
When was CVE-2022-42889 disclosed?
CVE-2022-42889 was first published on October 13, 2022, with the most recent update on November 21, 2024. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2022-42889 actively exploited?
CVE-2022-42889 is not currently on CISA's Known Exploited Vulnerabilities catalog. EchelonGraph's EG-KEV model classifies it as weaponized: a functional public exploit exists. FIRST EPSS estimates a 100% probability of exploitation in the next 30 days (99th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2022-42889?
CVE-2022-42889 has a CVSS v3 base score of 9.8 (NVD). The EG score is currently aggregating — additional source signals are being incorporated as they become available..
How do I remediate CVE-2022-42889?
A fix for CVE-2022-42889 is available: update to the fixed version the vendor names in its advisory. The vendor advisories EchelonGraph has for CVE-2022-42889 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-42889

Explore →

Is Your Infrastructure Affected by CVE-2022-42889?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.