Vulnerability record · CVE-2022-42889 · published 13 October 2022
CVE-2022-42889: Apache Commons Text interpolation allows remote code execution
Apache · Commons Text
Apache Commons Text versions 1.5 through 1.9 enable default StringLookup interpolators (script, dns, url) that can execute code or contact remote servers when untrusted values are interpolated. Applications relying on the default interpolation behavior are exposed to remote code execution. The flaw is fixed in 1.10.0, which disables the problematic interpolators by default.
Description
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and near-maximum EPSS make this a top remediation target despite absence from KEV.
What it is
Apache Commons Text versions 1.5 through 1.9 enable default StringLookup interpolators (script, dns, url) that can execute code or contact remote servers when untrusted values are interpolated. Applications relying on the default interpolation behavior are exposed to remote code execution. The flaw is fixed in 1.10.0, which disables the problematic interpolators by default.
Impact
An attacker who can influence interpolated input can execute arbitrary code in the JVM or force outbound requests to attacker-controlled or internal systems. This yields full compromise of confidentiality, integrity and availability of the affected application.
Attack surface
Reached over the network through any application path that passes untrusted configuration or user-supplied values into Commons Text interpolation. The CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is near maximum (0.99931, 99.969th percentile) and public references include a Packet Storm remote code execution write-up, indicating active interest and likely exploit availability.
What to do
- Upgrade Apache Commons Text to 1.10.0 or later, which disables the script, dns and url interpolators by default.
- If immediate upgrade is not possible, remove or restrict the default interpolators by constructing a custom StringSubstitutor with an explicit, minimal StringLookup set.
- Audit application code and configuration for untrusted values passed into StringSubstitutor or interpolated strings, and sanitize or reject ${...} patterns from external input.
- Track vendor advisories for bundled products (NetApp BlueXP, Juniper Security Threat Response Manager) and apply their patched releases.
- Restrict outbound network access from application servers to limit dns and url lookup abuse.
Detection
- Search application and dependency inventories for Apache Commons Text versions 1.5 through 1.9.
- Monitor logs and process telemetry for JVM script engine invocation or unexpected child processes spawned by Java applications.
- Alert on outbound DNS or HTTP requests originating from application servers to unusual or internal destinations.
- Inspect request and configuration inputs for ${script:, ${dns: or ${url: interpolation patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-42889 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42889), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.