myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889)

myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889)

Alert
TL;DR myDRE is NOT vulnerable for Text4Shell (CVE-2022-42889).

The National Cyber Security Center (NCSC) has announced that a vulnerability with impact High/High (CVE-2022-42889) has been identified in Apache Commons Text v1.5-v1.9. It is being expected that this will gain media attention as a public exploit code has become available that shows how to abuse this vulnerability that gives attackers a way of running malicious code remotely on vulnerable systems. It has also been linked to the Apache Log4J (Log4Shell) vulnerability earlier this year (myDRE is NOT vulnerable for CVE-2021-4428 - Apache Log4J2) and has been dubbed Text4Shell. 

However, according to the NCSC the attack surface for Text4Shell is more limited due to Apache Commons Text being used for rather specific applications.

Idea
myDRE does NOT use Apache Commons Text.

Read more about the official Text4Shell announcement here (Dutch): https://www.digitaltrustcenter.nl/nieuws/kwetsbaarheid-in-apache-commons-text.
Or a more elaborate article here (English): https://www.darkreading.com/application-security/apache-commons-vulnerability-patch-but-dont-panic.