GHSA-2gh6-wc3m-g37fCriticalCVSS 9.8Disclosed before NVD

hermes-management is vulnerable to RCE due to Apache commons-jxpath

Published
September 17, 2024
Last Modified
August 31, 2026

📋 Description

Impact

hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.

Patches

Upgrade Hermes to at least hermes-2.2.9

References

https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/

🎯 Affected products1

  • maven/pl.allegro.tech.hermes:hermes-management:>= 0.8.2, < 2.2.9

🔗 References (5)