Description
Apache Commons Text is a library focused on algorithms working on strings. Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. Versions prior to 1.10.0 are vulnerable to RCE when untrusted input is used inside variable interpolation due to insecure interpolation defaults. The vulnerability affects the StringSubstitutor interpolator class, which is included in the Commons Text library.
Remediation
Upgrade to Apache Commons Text 1.10.0.
References
Related Vulnerabilities
Juniper Junos OS J-Web RCE (CVE-2023-36845/CVE-2023-36846)
WordPress Plugin Statistics Remote Code Execution (1.8)
WordPress Plugin Loco Translate PHP Code Injection (2.5.3)
Security update: Hotfix available for ColdFusion
WordPress 'wp-admin/options.php' Remote Code Execution Vulnerability (0.6.2 - 2.3.2)