Netskope Threat Labs

CVE-2022-42889

ATP Sandbox Adv. HeuristicsAV

CVE-2022-42889 (Text4Shell) is a remote code execution vulnerability in Apache Commons Text that allows cyberattackers to execute arbitrary code by injecting malicious expressions into template evaluation. Applications that passed untrusted input through the library's variable interpolation could run malicious code on the server. Exploitation required specific usage patterns, but the library's enormous adoption made the flaw a widespread patching priority after disclosure.

First seen
November 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.Exploit.CVE-2022-42889.A.FFFFFFFE
Dropped:Generic.Exploit.CVE-2022-42889.A.312FB79B
Dropped:Generic.Exploit.CVE-2022-42889.A.46F789D7
Dropped:Generic.Exploit.CVE-2022-42889.A.6DB822BB
Dropped:Generic.Exploit.CVE-2022-42889.A.7ADECCC6
Dropped:Generic.Exploit.CVE-2022-42889.A.887589BD
Dropped:Generic.Exploit.CVE-2022-42889.A.90C29DD0
Dropped:Generic.Exploit.CVE-2022-42889.A.9C64C355
Dropped:Generic.Exploit.CVE-2022-42889.A.C5DFECA4
Dropped:Generic.Exploit.CVE-2022-42889.A.D0AF997C