{"id":"GHSA-2gh6-wc3m-g37f","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2gh6-wc3m-g37f","summary":"hermes-management is vulnerable to RCE due to Apache commons-jxpath","details":"### Impact\nhermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.\n\n### Patches\nUpgrade Hermes to at least hermes-2.2.9\n\n### References\nhttps://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/","published":"2024-09-17T19:29:24Z","modified":"2026-08-31T23:15:07.884111105Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"pl.allegro.tech.hermes:hermes-management","fixedVersion":"2.2.9"}],"fix":{"url":"https://github.com/allegro/hermes/commit/72ecc5aa41e37fd614443dd35d9200b66a61afb1","label":"allegro/hermes@72ecc5a"},"references":[{"type":"WEB","url":"https://github.com/allegro/hermes/security/advisories/GHSA-2gh6-wc3m-g37f"},{"type":"WEB","url":"https://github.com/allegro/hermes/commit/72ecc5aa41e37fd614443dd35d9200b66a61afb1"},{"type":"WEB","url":"https://github.com/allegro/hermes/commit/92d4ad0cf6868ba784707772b78e129fedff7a31"},{"type":"PACKAGE","url":"https://github.com/allegro/hermes"},{"type":"WEB","url":"https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T23:15:07.884111105Z"}}