hermes-management is vulnerable to RCE due to Apache commons-jxpath
Package
Affected versions
< 2.2.9
Patched versions
2.2.9
Description
Published to the GitHub Advisory Database
Sep 17, 2024
Reviewed
Sep 17, 2024
Last updated
Sep 17, 2024
Impact
hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.
Patches
Upgrade Hermes to at least hermes-2.2.9
References
https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/
References