CRITICAL9.8
GHSA-2gh6-wc3m-g37f
hermes-management is vulnerable to RCE due to Apache commons-jxpath
Quick fix
GHSA-2gh6-wc3m-g37f — pl.allegro.tech.hermes:hermes-management: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.2.9</version> for pl.allegro.tech.hermes:hermes-managementDetails
### Impact hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.
### Patches Upgrade Hermes to at least hermes-2.2.9
### References https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/pl.allegro.tech.hermes:hermes-management
Introduced in:
0.8.2Fixed in: 2.2.9Fix
# pom.xml: bump <version>2.2.9</version> for pl.allegro.tech.hermes:hermes-managementReferences
- https://github.com/allegro/hermes/security/advisories/GHSA-2gh6-wc3m-g37f[WEB]
- https://github.com/allegro/hermes/commit/72ecc5aa41e37fd614443dd35d9200b66a61afb1[WEB]
- https://github.com/allegro/hermes/commit/92d4ad0cf6868ba784707772b78e129fedff7a31[WEB]
- https://github.com/allegro/hermes[PACKAGE]
- https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852[WEB]