1415 - Text4Shell vulnerability

Modified on Tue, 5 Aug at 1:18 PM

Background

Similar to the Spring4Shell and Log4Shell vulnerabilities, a new critical vulnerability CVE-2022-42889, known as "Text4Shell", was discovered on 13 October 2022. Text4Shell is a vulnerability in the Java library Apache Commons Text and can allow an attacker to execute arbitrary code on the victim's machine. Read more here.

 

Mitigation

The Redstor ESE application does depend on a version of the Apache Commons Text library that is affected by CVE-2022-42889. However, ESE does not use the vulnerable string interpolation functions and is not susceptible to attack through this library.

As a precaution, ESE agents of version 22.11 and later no longer include the Apache Commons Text library.

We recommend regularly updating your Redstor software to ensure optimal security and functionality. You can find our latest downloads here.

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article