Layer7 API Management

 View Only
  • 1.  Apache Commons Text Vulnerability Security

    Posted Oct 20, 2022 02:01 AM
    I'd like to inquire about Apache Commons Text Vulnerability Security.
    Vulnerability in Remote Code Execution (CVE-2022-42889)
    There is a security vulnerability issue and the ca api gateway 10.1 is using commons-text-1.7.jar.
    Will it be resolved if I upgrade to commons-text-1.10.jar?


  • 2.  RE: Apache Commons Text Vulnerability Security

    Broadcom Employee
    Posted Oct 20, 2022 11:29 AM
    Hello, @Jaekwang Kim. We are aware of this CVE. However, the gateway's usage of the commons text library is limited to XML escaping functionality and does not use 'commons-text' interpolators for string lookups (vulnerable code), so there is no actual impact on the gateway. At this time, you cannot remove/upgrade the library on your own, because the gateway is making use of its 'StringEscapeUtils' class for XML escaping. This CVE will have to be resolved by Layer7 in a future CR.​

    ------------------------------
    Ben Urbanski
    Product Manager, API Gateway
    Layer7 API Management
    ------------------------------