A AegiFlow
CRITICALCVSS 9.3

GHSA-2gh6-wc3m-g37f

hermes-management is vulnerable to RCE due to Apache commons-jxpath

Published
2024-09-17
Modified
2026-08-31
Sources
github-advisory

Summary

### Impact hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath. ### Patches Upgrade Hermes to at least hermes-2.2.9 ### References https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenpl.allegro.tech.hermes:hermes-management2.2.9

Remediation: Upgrade to 2.2.9 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.