MAVEN · SEPTEMBER 2024 · EARLY WARNING

hermes-management RCE Vulnerability Due to Apache commons-jxpath

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
hermes-management (maven)
Patched version
2.2.9
CVE-2022-41852GHSA-2GH6-WC3M-G37F

An early warning has been issued for a remote code execution vulnerability in the hermes-management package due to a flaw in Apache commons-jxpath. Users of affected versions are advised to take immediate action.

What happened

An early warning has been issued regarding a remote code execution vulnerability in the hermes-management package. This vulnerability arises from a flaw in the Apache commons-jxpath library, which is used by hermes-management for processing user-controlled data. The vulnerability could allow an attacker to execute arbitrary code on a system running an affected version of hermes-management.

The vulnerability was first flagged on September 17, 2024. It is currently classified as a critical severity issue. The affected versions of hermes-management are those that use Apache commons-jxpath and are prior to version 2.2.9. The vulnerability has not been reported as exploited in the wild at this time.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If hermes-management is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your project uses hermes-management with a version that is prior to 2.2.9 and includes Apache commons-jxpath.

What should I do right now?

Immediately upgrade hermes-management to at least version 2.2.9 to mitigate the vulnerability.

Is there a patched version available?

Yes, hermes-management version 2.2.9 is the patched version that addresses this vulnerability.

Sources

Join the 0Day waitlist →

← Back to all threats