VDB
Sign up
CRITICAL9.8

GHSA-2gh6-wc3m-g37f

hermes-management is vulnerable to RCE due to Apache commons-jxpath

Quick fix

GHSA-2gh6-wc3m-g37f — pl.allegro.tech.hermes:hermes-management: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.2.9</version> for pl.allegro.tech.hermes:hermes-management

Details

### Impact hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.

### Patches Upgrade Hermes to at least hermes-2.2.9

### References https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/pl.allegro.tech.hermes:hermes-management
Introduced in: 0.8.2Fixed in: 2.2.9
Fix# pom.xml: bump <version>2.2.9</version> for pl.allegro.tech.hermes:hermes-management

References