Critical Vulnerabilities 2022 Incident #57 CVE-2022-42889

Text4Shell (CVE-2022-42889)

Estimated Financial Impact
Active scanning
Blast Radius
CVSS 9.8; Apache Commons Text

What Happened

An RCE vulnerability (CVSS 9.8) in Apache Commons Text, exploitable via specific usage patterns. Active scanning from Russian and Chinese IP space was observed shortly after disclosure. Frequently compared to Log4Shell given the Apache Commons pedigree.

✓

Risk Guard: Caught

VULN_RECENT_FREQUENCY + maintainer health preconditions

Risk Guard Check Codes That Flag This Incident

VULN_RECENT_FREQUENCY

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught VULN_RECENT_FREQUENCY + maintainer health preconditions
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; reactive not proactive
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← Spring4Shell (CVE-2022-22965) Lodash prototype pollution →