Loading
Feature Disruption - Service Cloud VoiceRead More
Feature degradation | Gmail Email delivery failureRead More

Security Vulnerabilities CVE-2022-42889 and CVE-2022-33980

Publish Date: Apr 13, 2024
Description
Apache Commons Text versions 1.5 - 1.9 and Apache Commons Configuration versions 2.4 - 2.7 are impacted by CVE-2022-42889 and CVE-2022-33980. Using untrusted values in the methods StringSubstitutor.replace or StringSubstitutor.replaceIn, an attacker could potentially execute a remote code execution (RCE) attack.
Resolution
Based on currently available information, Tableau products are not impacted by CVE-2022-42889 or CVE-2022-33980 because Tableau does not use the vulnerable methods StringSubstitutor.replace or StringSubstitutor.replaceIn.
Additional Resources
National Vulnerability Database (NVD) links:
 
Knowledge Article Number

001497009

 
Loading
Salesforce Help | Article