Loading

Security Vulnerabilities CVE-2022-42889 and CVE-2022-33980

Publiseringsdato: Apr 13, 2024
Beskrivelse
Apache Commons Text versions 1.5 - 1.9 and Apache Commons Configuration versions 2.4 - 2.7 are impacted by CVE-2022-42889 and CVE-2022-33980. Using untrusted values in the methods StringSubstitutor.replace or StringSubstitutor.replaceIn, an attacker could potentially execute a remote code execution (RCE) attack.
Løsning
Based on currently available information, Tableau products are not impacted by CVE-2022-42889 or CVE-2022-33980 because Tableau does not use the vulnerable methods StringSubstitutor.replace or StringSubstitutor.replaceIn.
Flere ressurser
National Vulnerability Database (NVD) links:
 
Knowledge-artikkelnummer

001497009

 
Laster
Salesforce Help | Article