CVE-2022-42889 was published in the National Vulnerability Database on 13 October, 2022. More information can be found here.
The vulnerability is caused with the use of Apache Commons Text 1.5 through 1.9. Is Automic Automation affected by this?
No components are impacted by this vulnerability. Please see details below for those have use the Apache commons-text library:
Update: 24 October 2022: Resolution updated: No components are fully affected
Update: 20 October 2022: The core components for Automation Engine are not impacted on 12.3. Broadcom Support and Engineering are continuing to look into if there is an impact on 21.0 as well as agents.
Update 19 October 2022: Broadcom Support and Engineering is looking into this on priority.
Please check back on this article regularly for updates.