CVE-2022-42889 in commons-text-api Jenkins Plugin

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Hello,

       

      https://plugins.jenkins.io/commons-text-api/ is using

      org.apache.commons.commons-text:1.0.9 

      which is vulnerable to CVE-2022-42889

      Refer https://nakedsecurity.sophos.com/2022/10/18/dangerous-hole-in-apache-commons-text-like-log4shell-all-over-again/

       

      Please upgrade version of org.apache.commons:commons-text to 1.10 to fix the RCE.

            Assignee:
            Unassigned
            Reporter:
            Rosan Arya
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: