Hello,
This recent vulnerability has been detected. It seems to be a vulnerability in Apache Commons Text.
The affected versions of Apache Commons Text are 1.5 to 1.9.
Does this affect Commvault too?
Hello,
This recent vulnerability has been detected. It seems to be a vulnerability in Apache Commons Text.
The affected versions of Apache Commons Text are 1.5 to 1.9.
Does this affect Commvault too?
Hi
I looked into this and found that we are not using this Apache product and are not vulnerable to this.
Let me know if you have any further questions!
Hi Mike, I think this will do. Thanks for you answer!
Anytime!
Our CV environment is using Apache for Command Center. So why CV saying we are not using Apache in our products? @Mike Struening
Nessus report scan found this:
Hi, If this is not used, can it be safety removed?
It is generating red alerts for at least one customer.
Hmmm… If it’s not used, it should be safe to remove I’d think.
Better yet, if it’s not used, why is it (still) installed at all?
No problem in installing/using 3rd party software along with Commvault, but it should not be left lingering unmaintained/vulnerable. I think with log4j we had a similar issue where old versions were left behind… :-(
I totally agree! Most obvious components are being updated often, but others are are being forgotten. Also even though Commvault doesn't use the specific function, library or feature than it might still show up in the results of security scans. For us this is not a problem because we can defend it easily, but for others it's harder because management looks for smileys and lack proper knowledge to interpreter the actual implementation and/or vulnerability.
As
Hi
Not sure if it is part of the Q&A process but having a test setup that is scanned every week by a software vulnerability manager could be something to add to the process. Just to make sure vulnerable packages and libraries are identified automatically so they can be addressed pro-actively.
Yep, Rapid7 also sees this component as vulnerable, if it’s not used, remove it! Commvault are certainly not alone in leaving components behind even after they no longer use them… If that is in fact the case that it’s no longer used, as others have said, compliance just want to see green ticks!
Apache Commons Text jars within the vulnerable version range found:
How is this resolved? Documentation says there will be a future update.
https://documentation.commvault.com/2022e/essential/146231_security_vulnerability_and_reporting.html
Advisory ID: CV_2022_10_1
External Reporting ID: CVE-2022-42889
Issued On: October 18, 2022
Updated On: October 18, 2022
Severity: High
Affected Products
The vulnerability does not affect Commvault products.
Resolution
As a precautionary measure, we are upgrading the Apache Commons Text version in our product. The updates will be available in an upcoming Maintenance Release.
If you need the details for another Feature Release, let me know.
Thanks Mike but after upgrading to 11.28.35 I see it only updated in AdminConsole, not in CustomeReportsEngine. Will open a ticket.
\Program Files\Commvault\ContentStore\AdminConsole\WEB-INF\lib\commons-text-1.10.0.jar
\Program Files\Commvault\ContentStore\CustomReportsEngine\WEB-INF\lib\commons-text-1.9.jar
You beat me to the punch! Keep me posted
For 11.24, it’s Form ID 5772. Still in progress, but on its way (doesn’t show an ETA).
Hello Mike,
do we have any update now for 11.24 Form ID 5772 ETA?
And do we have any news about the problem regarding commons-text?
\Program Files\Commvault\ContentStore\AdminConsole\WEB-INF\lib\commons-text-1.10.0.jar
\Program Files\Commvault\ContentStore\CustomReportsEngine\WEB-INF\lib\commons-text-1.9.jar
Hello Onno,
yes, i would be glad to receive an answer.
Hello
can you tell me, if there is any update now for 11.24 Form ID 5772 ETA?
And do we have any news about the problem regarding commons-text?
\Program Files\Commvault\ContentStore\AdminConsole\WEB-INF\lib\commons-text-1.10.0.jar
\Program Files\Commvault\ContentStore\CustomReportsEngine\WEB-INF\lib\commons-text-1.9.jar
Thanks Tobi
From the release documentation, Looks like it was in the January 2023 update - 11.24.86
“
Update commons-text library to the latest version to address CVE-2022-42889 concerns. | 6640, 6641, 6642 |
”
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.