← Retour
GHSA-2gh6-wc3m-g37f
hermes-management is vulnerable to RCE due to Apache commons-jxpath
Résumé
hermes-management is vulnerable to RCE due to Apache commons-jxpath
Paquets affectés
maven
pl.allegro.tech.hermes:hermes-management
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.9"}]}]
Références
- web https://github.com/allegro/hermes/security/advisories/GHSA-2gh6-wc3m-g37f
- web https://github.com/allegro/hermes/commit/72ecc5aa41e37fd614443dd35d9200b66a61afb1
- web https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852
- web https://github.com/allegro/hermes/commit/92d4ad0cf6868ba784707772b78e129fedff7a31
- web https://github.com/advisories/GHSA-2gh6-wc3m-g37f