Executive brief
Hermes is a message broker platform used for event streaming and message management across distributed systems. A critical vulnerability in Hermes-management allows unauthenticated attackers to execute arbitrary code remotely by sending specially crafted requests that exploit a flaw in the Apache Commons JXPath library. This could allow attackers to gain full control of affected systems, access sensitive data, or disrupt message delivery operations.
Technical details
This vulnerability is a remote code execution (RCE) flaw stemming from hermes-management's dependency on Apache Commons JXPath (related to CVE-2022-41852). The vulnerable component processes user-supplied input through JXPath expressions without proper sanitization, allowing attackers to inject malicious XPath expressions that execute arbitrary code. The attack vector is network-based, requires no authentication or privileges, no user interaction, and no attack complexity mitigation. By crafting a malicious JXPath expression in user-controlled input, an attacker can achieve arbitrary code execution with the privileges of the hermes-management process. The vulnerability affects versions 0.8.2 through 2.2.8; upgrading to Hermes 2.2.9 or later patches this issue.
Affected products
- Allegro Hermes >= 0.8.2, < 2.2.9
Timeline
- 2024-09-17: disclosed: GitHub Security Advisory GHSA-2gh6-wc3m-g37f published
- 2024-09-17: patched: Hermes 2.2.9 released with patch