Announcement

Collapse

Mirth Connect 4.3.0 Released!

Mirth Connect 4.3.0 is now available as an appliance update and on our GitHub page.

This is a major release containing new features like adding new functionality to the Mirth Connect Setup Wizard, adding the ability for resource and channel-specific classloaders to load child-first or parent-first, and added a default implementation of the getObjectsForSwaggerExamples() method in the ServicePlugin class. This release also contains enhancements for the Mirth Connect Administrator Launcher, the Mirth Connect Docker images, and several bug fixes and security improvements.

Download | See What's New | Upgrade Guide | Release Notes

For discussion on this release, see this thread.
See more
See less

CVE-2022-42889 vulnerability in commons-text-1.8.jar

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • CVE-2022-42889 vulnerability in commons-text-1.8.jar

    Mirth Connect uses commons-text-1.8.jar as a helper library and it is vulnerable to “CVE-2022-42889 (Text4Shell Apache Commons Text vulnerability)”. Is there a way to patch this? Any solutions?

    The library org.apache.commons:commons-text version 1.8 was detected in Maven library manager located at C:\Program Files\Mirth Connect\manager-lib\commons-text-1.8.jar and is vulnerable to CVE-2022-42889, which exists in versions >= 1.5, < 1.10.0.
    The library org.apache.commons:commons-text version 1.8 was detected in Maven library manager located at C:\Program Files\Mirth Connect\cli-lib\commons-text-1.8.jar and is vulnerable to CVE-2022-42889, which exists in versions >= 1.5, < 1.10.0.

    The library org.apache.commons:commons-text version 1.8 was detected in Maven library manager located at C:\Program Files\Mirth Connect\.install4j\user\commons-text-1.8.jar and is vulnerable to CVE-2022-42889, which exists in versions >= 1.5, < 1.10.0.
    The library org.apache.commons:commons-text version 1.8 was detected in Maven library manager located at C:\Program Files\Mirth Connect\client-lib\commons-text-1.8.jar and is vulnerable to CVE-2022-42889, which exists in versions >= 1.5, < 1.10.0.
    The library org.apache.commons:commons-text version 1.8 was detected in Maven library manager located at C:\Program Files\Mirth Connect Administrator Launcher\cache\4.1.1\core\commons-text-1.8.jar and is vulnerable to CVE-2022-42889, which exists in versions >= 1.5, < 1.10.0.

    Is it okay to manually download commons-text-1.10 and replace 1.8?


    Below is the output from the Wiz security posture tool.

    dataurl514556.png
    Last edited by harshamw; 03-17-2023, 12:39 AM.

  • #2
    @harshamw​ - best place to post stuff like that is over on mirth github at https://github.com/nextgenhealthcare/connect/issues.

    Do make sure it hasn't been reported which it has at https://github.com/nextgenhealthcare...ct/issues/5474.

    Note fixed in https://github.com/nextgenhealthcare...o-version-1100
    Diridium Technologies, Inc.
    https://diridium.com

    Comment

    Working...
    X