Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2025-12-16T19:35:46.485Z
Reserved: 2025-04-22T21:13:49.959Z
Link: CVE-2025-46295
No data.
Status : Received
Published: 2025-12-16T18:16:12.477
Modified: 2025-12-16T20:15:48.177
Link: CVE-2025-46295
No data.
OpenCVE Enrichment
No data.