Skip to content

hermes-management is vulnerable to RCE due to Apache commons-jxpath

Critical
moscicky published GHSA-2gh6-wc3m-g37f Sep 17, 2024

Package

No package listed

Affected versions

< 2.2.9

Patched versions

2.2.9

Description

Impact

hermes-management is vulnerable to RCE when it processes user-controlled
data due to using Apache commons-jxpath.

Patches

Upgrade Hermes to at least hermes-2.2.9

References

https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs