We recently became aware of a Java vulnerability in the Apache Commons Text library [CVE-2022-42889] that could allow for code injection by a malicious actor. While Jamf Pro, Jamf Now, Jamf School, Jamf Threat Defense, Jamf Data Policy, Infrastructure Manager, and Jamf Private Access do utilize this library, a thorough review has shown that these products are not vulnerable to this attack.
Although the products themselves are not vulnerable to this attack, upcoming releases of Jamf Pro, Jamf Now, Jamf School, Jamf Threat Defense, Jamf Data Policy, Infrastructure Manager, and Jamf Private Access will contain updates to this vulnerable library.
If you have any questions or experience any issues during this process, contact Jamf Support for assistance.
Aaron Kiemele
CISO, Jamf