Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in WhatsAppParser caused by Apache Commons Text 1.8 dependency #1374

Closed
lfcnassif opened this issue Oct 14, 2022 · 2 comments
Closed
Assignees
Labels
bug dependencies Pull requests that update a dependency file

Comments

@lfcnassif
Copy link
Member

I'm not sure if it affects us, but since CVE-2022-42889 is a about a possible RCE, it's safer to upgrade the library.

@lfcnassif lfcnassif added bug dependencies Pull requests that update a dependency file labels Oct 14, 2022
@lfcnassif lfcnassif self-assigned this Oct 14, 2022
@lfcnassif lfcnassif changed the title Vulnerability in Apache Commons Text 1.8 dependency Vulnerability in WhatsAppParser caused by Apache Commons Text 1.8 dependency Oct 19, 2022
@lfcnassif
Copy link
Member Author

lfcnassif commented Oct 19, 2022

I just received a private POC about this by Xavier from Fastly, forwarded by CERT.br, where arbitrary local commands could be executed by WA parser. Original POC sent didn't work, because we perform a basic clean up of all message body strings, but it was easy to fix the POC and execute "calc.exe" in examiners machine while processing the case.

So I'll roll a 4.0.6 fixing release.

@lfcnassif
Copy link
Member Author

Affects 3.18.1 <= version <= 4.0.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

1 participant