Uploaded image for project: 'Livy'
  1. Livy
  2. LIVY-897

Upgrade Commons Text to 1.10.0

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Critical
    • Resolution: Unresolved
    • None
    • 0.9.0
    • None
    • None

    Description

      Apache Commons Text versions prior to 1.10.0 are vulnerable to CVE-2022-42889, which involves potential script execution when processing untrusted input using StringLookup. Direct and transitive references to Apache Commons Text prior to 1.10.0 should be upgraded to avoid the default interpolation behavior.

      Attachments

        Activity

          People

            Unassigned Unassigned
            jasonmadam Jason-Morries Adam
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: