You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
lfcnassif
changed the title
Vulnerability in Apache Commons Text 1.8 dependency
Vulnerability in WhatsAppParser caused by Apache Commons Text 1.8 dependency
Oct 19, 2022
I just received a private POC about this by Xavier from Fastly, forwarded by CERT.br, where arbitrary local commands could be executed by WA parser. Original POC sent didn't work, because we perform a basic clean up of all message body strings, but it was easy to fix the POC and execute "calc.exe" in examiners machine while processing the case.
I'm not sure if it affects us, but since CVE-2022-42889 is a about a possible RCE, it's safer to upgrade the library.
The text was updated successfully, but these errors were encountered: