Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-81045

Upgrade Apache Commons-text for CVE-2022-42889 - DUPLICATED

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Low Low
    • None
    • 7.13.11, 7.19.2
    • Security
    • None

      This bug was created to track the change required to upgrade the Apache Commons Text library and can be used by customers to follow its progress and get notified on the next numbered release.

      Confluence does not use the vulnerable module org.apache.commons.text.StringSubstitutor

      Issue Summary

      Apache Common Text library should be upgraded to 1.10.0 or later to mitigate any exploiting attempts listed on CVE-2022-42889

      Steps to Reproduce

      Check org.apache.commons -> commons-text version on pom.xml

      Expected Results

      apache-common-text 1.10.0+ is expected

      Actual Results

      apache-common-text 1.9 (or earlier) is used

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available

          Form Name

            [CONFSERVER-81045] Upgrade Apache Commons-text for CVE-2022-42889 - DUPLICATED

            How should I upgrade common-text  version to 1.10.0 on centos

             

            Naman Jain added a comment - How should I upgrade common-text  version to 1.10.0 on centos  

            Eliza Jamison added a comment - - edited

            So this is a known issue and a critical vulnerability that need to be fixed within 2 weeks to stay compliant.  This says closed with no fix?????  My security team can force my applications offline.   I have 3 Jira instances.

            Eliza Jamison added a comment - - edited So this is a known issue and a critical vulnerability that need to be fixed within 2 weeks to stay compliant.  This says closed with no fix?????  My security team can force my applications offline.   I have 3 Jira instances.

            UB added a comment -

            UB added a comment - https://jira.atlassian.com/browse/CONFSERVER-81048

              Unassigned Unassigned
              ubreier@atlassian.com UB
              Affected customers:
              0 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: