CRITICALCVSS 9.3
GHSA-2gh6-wc3m-g37f
hermes-management is vulnerable to RCE due to Apache commons-jxpath
Summary
### Impact hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath. ### Patches Upgrade Hermes to at least hermes-2.2.9 ### References https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Maven | pl.allegro.tech.hermes:hermes-management | — | 2.2.9 |
Remediation: Upgrade to 2.2.9 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.