{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ajunipersecurity_threat_response_manager7.5.0up3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:commons_text:*:*:*:*:*:*:*:*","cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:*","cpe:2.3:a:juniper:security_threat_response_manager:*:*:*:*:*:*:*:*","cpe:2.3:a:juniper:security_threat_response_manager:7.5.0:-:*:*:*:*:*:*","cpe:2.3:a:juniper:security_threat_response_manager:7.5.0:up1:*:*:*:*:*:*","cpe:2.3:a:juniper:security_threat_response_manager:7.5.0:up2:*:*:*:*:*:*","cpe:2.3:a:juniper:security_threat_response_manager:7.5.0:up3:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2022-42889"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Commons Text (1.5-1.9)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","java","apache"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eCVE-2022-42889, widely known as Text4Shell, is a remote code execution (RCE) vulnerability affecting Apache Commons Text versions 1.5 through 1.9. The vulnerability arises from the default behavior of the 'StringSubstitutor' interpolator object, which uses the 'StringLookupFactory' to perform string lookups. When an application passes unsanitized user-supplied input to the 'StringSubstitutor.replace()' or 'replaceIn()' methods, an attacker can provide a specially crafted string using the '${prefix:name}' syntax.\u003c/p\u003e\n\u003cp\u003eIf the application is running on an environment that supports specific lookups, such as 'script', 'dns', or 'url', an attacker can trigger arbitrary command execution or unauthorized network requests. While modern JDK versions have removed the Nashorn JavaScript engine, the vulnerability remains exploitable in environments where third-party script engines like JEXL are present in the classpath. Defenders should treat this as a high-priority risk for any Java-based applications utilizing these affected versions of the Apache Commons Text library.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a web application utilizing Apache Commons Text (v1.5-1.9) that passes user input to 'StringSubstitutor.replace()'.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload using interpolation syntax, for example: '${script:javascript:java.lang.Runtime.getRuntime().exec('command')}'.\u003c/li\u003e\n\u003cli\u003eAttacker delivers the payload through a common web vector, such as an HTTP GET query parameter (e.g., '?data=${payload}') or a POST request body.\u003c/li\u003e\n\u003cli\u003eThe vulnerable application receives the request and passes the malicious string to the 'StringSubstitutor' interpolation engine.\u003c/li\u003e\n\u003cli\u003eThe library processes the '${script:...}' prefix, triggering the underlying scripting engine (Nashorn or JEXL).\u003c/li\u003e\n\u003cli\u003eThe scripting engine executes the injected command with the privileges of the web application server process.\u003c/li\u003e\n\u003cli\u003eIf successful, the attacker gains RCE, enabling lateral movement, data exfiltration, or further malware deployment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution, granting the attacker full control over the vulnerable server process. This vulnerability affects any enterprise Java ecosystem using the vulnerable versions of Apache Commons Text. Given the ubiquitous nature of this library, the potential scope includes a broad range of web applications, middleware, and backend services, leading to potential complete system compromise and data breach.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Apache Commons Text to version 1.10.0 or later immediately to eliminate the vulnerable interpolation behavior.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) rules to inspect incoming HTTP requests for suspicious patterns containing '${' followed by 'script:', 'dns:', or 'url:' prefixes.\u003c/li\u003e\n\u003cli\u003ePerform a dependency scan across all enterprise Java applications to identify and remediate instances of 'commons-text' versions 1.5-1.9 using SCA (Software Composition Analysis) tools.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for unexpected system calls originating from the Java runtime process, particularly those invoking command shells like 'bash', 'sh', or 'cmd.exe'.\u003c/li\u003e\n\u003cli\u003eIn environments where upgrading is not immediately feasible, implement strict input validation to prevent user-supplied data from reaching string interpolation methods.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-23T17:57:29Z","date_published":"2026-09-23T17:57:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-text4shell/","summary":"CVE-2022-42889, or Text4Shell, is a critical remote code execution vulnerability in Apache Commons Text versions 1.5-1.9 that allows attackers to execute arbitrary code via malicious string lookups.","title":"Critical Remote Code Execution in Apache Commons Text (CVE-2022-42889)","url":"https://feed.craftedsignal.io/briefs/2026-09-text4shell/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:juniper:security_threat_response_manager:7.5.0:up3:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}