HIGH7.7
GHSA-4jrv-ppp4-jm57
Deserialization of Untrusted Data in Gson
Quick fix
GHSA-4jrv-ppp4-jm57 — com.google.code.gson:gson: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.8.9</version> for com.google.code.gson:gsonDetails
The package `com.google.code.gson:gson` before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the `writeReplace()` method in internal classes, which may lead to denial of service attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.google.code.gson:gson
Introduced in:
0Fixed in: 2.8.9Fix
# pom.xml: bump <version>2.8.9</version> for com.google.code.gson:gsonReferences
- https://nvd.nist.gov/vuln/detail/CVE-2022-25647[ADVISORY]
- https://github.com/google/gson/pull/1991[WEB]
- https://github.com/google/gson/pull/1991/commits[WEB]
- https://github.com/google/gson[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html[WEB]
- https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html[WEB]
- https://security.netapp.com/advisory/ntap-20220901-0009[WEB]
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327[WEB]
- https://www.debian.org/security/2022/dsa-5227[WEB]
- https://www.oracle.com/security-alerts/cpujul2022.html[WEB]