Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Apache Commons Text: CVE-2022-42889

mbitzis June 20, 2023

Hello,

I would like to inquire whether the files related to Apache Commons Text: CVE-2022-42889 can be safely deleted, considering that they are not being utilized by the application itself?

Kindly,

Marios.

1 answer

1 accepted

0 votes
Answer accepted
Tim Perrault
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 20, 2023

Hello @mbitzis 

 

It looks like this is a bug they are actively working. From looking at some of the comments it looks like it has been fixed in version 9.6 so upgrading might be the way to go.

 

Disclaimer: Jira IS NOT vulnerable to CVE-2022-42889. Jira does not use the vulnerable module org.apache.commons.text.StringSubstitutor

Suggest an answer

Log in or Sign up to answer