Jakub Moravec created ARTEMIS-4069: -------------------------------------- Summary: CVE-2022-42889: commons-text-1.9 Key: ARTEMIS-4069 URL: https://issues.apache.org/jira/browse/ARTEMIS-4069 Project: ActiveMQ Artemis Issue Type: Bug Components: ActiveMQ-Artemis-Native Affects Versions: 2.26.0 Reporter: Jakub Moravec Assignee: Clebert Suconic
Based on [https://nvd.nist.gov/vuln/detail/CVE-2022-42889,] commons-text-1.9 (which is a transitive dependency of Artemis) is vulnerable due to the StringLookup feature. Please provide information about the impact (is Artemis vulnerable?), and ETA for upgrading to a non-vulnerable version. -- This message was sent by Atlassian Jira (v8.20.10#820010)