VDB
Sign up
HIGH7.7

GHSA-4jrv-ppp4-jm57

Deserialization of Untrusted Data in Gson

Quick fix

GHSA-4jrv-ppp4-jm57 — com.google.code.gson:gson: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.8.9</version> for com.google.code.gson:gson

Details

The package `com.google.code.gson:gson` before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the `writeReplace()` method in internal classes, which may lead to denial of service attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.google.code.gson:gson
Introduced in: 0Fixed in: 2.8.9
Fix# pom.xml: bump <version>2.8.9</version> for com.google.code.gson:gson

References