Loading

Security Vulnerabilities CVE-2022-42889 and CVE-2022-33980

Date de publication: Apr 13, 2024
Description
Apache Commons Text versions 1.5 - 1.9 and Apache Commons Configuration versions 2.4 - 2.7 are impacted by CVE-2022-42889 and CVE-2022-33980. Using untrusted values in the methods StringSubstitutor.replace or StringSubstitutor.replaceIn, an attacker could potentially execute a remote code execution (RCE) attack.
Résolution
Based on currently available information, Tableau products are not impacted by CVE-2022-42889 or CVE-2022-33980 because Tableau does not use the vulnerable methods StringSubstitutor.replace or StringSubstitutor.replaceIn.
Ressources supplémentaires
National Vulnerability Database (NVD) links:
 
Numéro d’article de la base de connaissances

001497009

 
Chargement
Salesforce Help | Article