hermes-management is vulnerable to RCE when it processes user-controlled data due to using Apache commons-jxpath.
Upgrade Hermes to at least hermes-2.2.9
https://hackinglab.cz/en/blog/remote-code-execution-in-jxpath-library-cve-2022-41852/
{ "nvd_published_at": null, "cwe_ids": [ "CWE-1395" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-09-17T19:29:24Z" }