hermes-management RCE Vulnerability Due to Apache commons-jxpath
- Severity
- HIGH
- Affected component
- hermes-management (maven)
- Patched version
- 2.2.9
An early warning has been issued for a remote code execution vulnerability in the hermes-management package due to a flaw in Apache commons-jxpath. Users of affected versions are advised to take immediate action.
What happened
An early warning has been issued regarding a remote code execution vulnerability in the hermes-management package. This vulnerability arises from a flaw in the Apache commons-jxpath library, which is used by hermes-management for processing user-controlled data. The vulnerability could allow an attacker to execute arbitrary code on a system running an affected version of hermes-management.
The vulnerability was first flagged on September 17, 2024. It is currently classified as a critical severity issue. The affected versions of hermes-management are those that use Apache commons-jxpath and are prior to version 2.2.9. The vulnerability has not been reported as exploited in the wild at this time.
What to do about it
- Upgrade hermes-management to at least version 2.2.9 to mitigate the remote code execution vulnerability.
- Review your project dependencies to identify any use of hermes-management and assess the version in use.
- If you are unable to upgrade immediately, consider implementing additional security measures to limit exposure, such as restricting access to the hermes-management service.
- Monitor the primary sources for updates on the vulnerability and any additional mitigation advice that may be provided.
How 0Day would have caught this
hermes-management is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your project uses hermes-management with a version that is prior to 2.2.9 and includes Apache commons-jxpath.
What should I do right now?
Immediately upgrade hermes-management to at least version 2.2.9 to mitigate the vulnerability.
Is there a patched version available?
Yes, hermes-management version 2.2.9 is the patched version that addresses this vulnerability.