Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability in Artifactory: CVE-2022-42889 Remote code execution vulnerability discovered in Apache Commons Text #1953

Closed
varadajadhav opened this issue Jan 10, 2025 · 1 comment

Comments

@varadajadhav
Copy link

Hello Team,

We have identified a security vulnerability in our Artifactory installation related to remote code execution in Apache Commons Text (CVE-2022-42889). During our investigation, we located the vulnerable package:
/opt/jfrog/artifactory/app/access/tomcat/webapps/access/WEB-INF/lib/commons-text-1.6.jar

Our current Artifactory version is 7.98.8. Could you confirm if this package is vulnerable in this version? If so, could you provide guidance on how to address this issue?

Please let me know if you need any additional details from my side.

Thank you!

@amithins
Copy link
Collaborator

Hi @varadajadhav, JFrog Platform is not affected by CVE-2022-42889, since it does not use the impacted packages. This info has been documented in the official doc on CVE's not impacting Artifactory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants