# CVE-2022-42889 Updated information

**URL:** <https://community.wowza.com/t/cve-2022-42889-updated-information/95591>\
**Category:** Wowza Streaming Engine\
**Created:** [November 7, 2022, 10:45pm UTC](https://community.wowza.com/t/cve-2022-42889-updated-information/95591 "2022-11-07T22:45:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [November 7, 2022, 10:45pm UTC](https://community.wowza.com/t/cve-2022-42889-updated-information/95591/1 "2022-11-07T22:45:47Z")

</div>

In regards to **CVE-2022-42889** , initial investigation shows that Wowza is not impacted, although we’re still reviewing the NIST CVE as they continue their investigation.

> Wowza Streaming Engine only uses the [escapeHtml4](https://commons.apache.org/proper/commons-text/apidocs/org/apache/commons/text/StringEscapeUtils.html#escapeHtml4-java.lang.String-:~:text=null%20string%20input-,escapeHtml4,-public%20static%20final) method from the StringEscapeUtils class, so as the CVE is currently written Wowza Streaming Engine is not impacted. We continue to monitor the CVE as it is currently “UNDERGOING REANALYSIS”. We will review further once they post updates on their findings.To proactively mitigate any concerns ensure each “live application” has source authentication enabled ( _it is configured this way by default_ ). We outline the process here: [Publish from RTMP/RTSP with authentication](https://www.wowza.com/docs/how-to-enable-username-password-authentication-for-rtmp-and-rtsp-publishing#configure-source-authentication-for-the-server0)

Moving forward, Wowza plans to integrate the updated Apache Commons Text component to 1.10 or later in the next Wowza Streaming Engine release in early 2023.

---

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [November 8, 2022, 2:57am UTC](https://community.wowza.com/t/cve-2022-42889-updated-information/95591/2 "2022-11-08T02:57:44Z")

</div>

Is that another apache java library issue ?

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [November 10, 2022, 4:02pm UTC](https://community.wowza.com/t/cve-2022-42889-updated-information/95591/3 "2022-11-10T16:02:17Z")

</div>

> [@Rose\_Power-Wowza\_Com](#):
>
> **CVE-2022-42889** ,

[https://nvd.nist.gov/vuln/detail/CVE-2022-42889](https://nvd.nist.gov/vuln/detail/CVE-2022-42889)

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [November 14, 2022, 10:24pm UTC](https://community.wowza.com/t/cve-2022-42889-updated-information/95591/4 "2022-11-14T22:24:25Z")

</div>

**UPDATE:**

> _(As of November 14, 2022 via the Wowza Streaming Engine Product Owner)_ After extensive investigation of the CVE as currently written, we have found that CVE-2022-42889 does not impact Wowza Streaming Engine. We are continuing to monitor the CVE as it is currently “UNDERGOING REANALYSIS”. We will review further once they’ve posted updates on their findings. To proactively mitigate any concerns ensure each “live application” has source authentication enabled (it is configured this way by default). We outline the process here:[Publish from RTMP/RTSP with authentication](https://www.wowza.com/docs/how-to-enable-username-password-authentication-for-rtmp-and-rtsp-publishing#configure-source-authentication-for-the-server0Moving) forward, to mitigate security scans reporting this Wowza plans to integrate the updated Apache Commons Text component 1.10 in the next Wowza Streaming Engine release in early 2023.
