Loading

Security Vulnerabilities CVE-2022-42889 and CVE-2022-33980

Julkaisupäivä: Apr 13, 2024
Kuvaus
Apache Commons Text versions 1.5 - 1.9 and Apache Commons Configuration versions 2.4 - 2.7 are impacted by CVE-2022-42889 and CVE-2022-33980. Using untrusted values in the methods StringSubstitutor.replace or StringSubstitutor.replaceIn, an attacker could potentially execute a remote code execution (RCE) attack.
Ratkaisu
Based on currently available information, Tableau products are not impacted by CVE-2022-42889 or CVE-2022-33980 because Tableau does not use the vulnerable methods StringSubstitutor.replace or StringSubstitutor.replaceIn.
Lisäresurssit
National Vulnerability Database (NVD) links:
 
Knowledge-artikkelin numero

001497009

 
Ladataan
Salesforce Help | Article