# Impact of CVE-2022-42889 on Elastic stack

**URL:** <https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858>\
**Category:** Elasticsearch\
**Created:** [October 18, 2022, 8:37am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858 "2022-10-18T08:37:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jgimenez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jgimenez/32/34681_2.png) [@jgimenez](https://discuss.elastic.co/u/jgimenez)\
**Post date:** [October 18, 2022, 8:37am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/1 "2022-10-18T08:37:14Z")

</div>

Hi there, is the Elastic software affected by CVE-2022-42889, and if so, what are the actions recommended? Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 18, 2022, 9:02am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/2 "2022-10-18T09:02:17Z")

</div>

Please see [Security issues | Elastic](https://www.elastic.co/community/security);

> Users and customers may report any other potential security issues to [security@elastic.co](mailto:security@elastic.co). This address can be used for product security related inquiries or requests about other security topics that are not explicitly mentioned here. We can accept only security issues at this address. Bug reports should be directed to the bug database of the project you're reporting it on or raised to Elastic Support.
> 
> If you would like to encrypt your message to us, please use our PGP key. The fingerprint is
> 
> 1224 D1A5 72A7 3755 B61A 377B 14D6 5EE0 D2AE 61D2
> 
> The key is available via keyservers; search for 'security@elastic.co'.

---

<div class="post-metadata">

**Author:** ![mgrafl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mgrafl/32/85895_2.png) [@mgrafl](https://discuss.elastic.co/u/mgrafl)\
**Post date:** [October 19, 2022, 9:22am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/3 "2022-10-19T09:22:15Z")

</div>

Hi @warkolm,  
Thanks for the link to "Security issues". However, the current absence of an advisory concerning CVE-2022-42889 does not conclusively say whether you have looked into the issue at all.

A clear statement whether Elastic products are affected or not by CVE-2022-42889 would be highly appreciated.

Thanks and best regards,  
Michael

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [October 20, 2022, 3:05am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/4 "2022-10-20T03:05:45Z")

</div>

Elastic products do not depend on commons-text, do not bundle commons-text and thus are not affected by CVE-2022-42889 in any way.

> Thanks for the link to "Security issues". However, the current absence of an advisory concerning CVE-2022-42889 does not conclusively say whether you have looked into the issue at all.

Thank you for your comment @mgrafl . As you can probably understand, there are tens of CVEs vulnerabilities being published every day. We cannot be adding an advisory for each one of them that does not affect Elastic products in any way as the noise would be so high that it would drown all the legitimate advisories that our users **need** to be informed about.

---

<div class="post-metadata">

**Author:** ![vbohata](https://avatars.discourse-cdn.com/v4/letter/v/a8b319/32.png) [@vbohata](https://discuss.elastic.co/u/vbohata)\
**Post date:** [October 24, 2022, 7:28am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/5 "2022-10-24T07:28:56Z")

</div>

Hello. Why is commons-text-1.3.jar included in support-diagnostics? Seems it is not required here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2022, 7:29am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858/6 "2022-11-21T07:29:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
