GHSA-2gh6-wc3m-g37fCriticalCVSS 9.8Disclosed before NVD
hermes-management is vulnerable to RCE due to Apache commons-jxpath
📋 Description
Impact
hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.
Patches
Upgrade Hermes to at least hermes-2.2.9
References
https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/
🎯 Affected products1
- maven/pl.allegro.tech.hermes:hermes-management:>= 0.8.2, < 2.2.9
🔗 References (5)
- https://github.com/allegro/hermes/security/advisories/GHSA-2gh6-wc3m-g37f
- https://github.com/allegro/hermes/commit/72ecc5aa41e37fd614443dd35d9200b66a61afb1
- https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852
- https://github.com/allegro/hermes/commit/92d4ad0cf6868ba784707772b78e129fedff7a31
- https://github.com/advisories/GHSA-2gh6-wc3m-g37f