Skip to content

Is RDF4J affected by CVE-2022-42889: Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults #4318

Discussion options

You must be logged in to vote

Since release 4.2.1, RDF4J is using commons-text 1.10.0 (see GH-4233). So unless you use a version of RDF4J older than that, it's not affected by this CVE.

However even for older versions of RDF4J this is unlikely to be an issue, since (as far as I'm aware) we do not make use variable interpolation anywhere in the project.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@PravinPrameKumar
Comment options

Answer selected by abrokenjester
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants