The National Cyber Security Center (NCSC) has announced that a vulnerability with impact High/High (
CVE-2022-42889) has been identified in Apache Commons Text v1.5-v1.9. It is being expected that this will gain media attention as a public exploit code has become available that shows how to abuse this vulnerability that gives attackers a way of running malicious code remotely on vulnerable systems. It has also been linked to the Apache Log4J (Log4Shell) vulnerability earlier this year (
myDRE is NOT vulnerable for CVE-2021-4428 - Apache Log4J2) and has been dubbed Text4Shell.
However, according to the NCSC the attack surface for Text4Shell is more limited due to Apache Commons Text being used for rather specific applications.