The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3001-1 | libgoogle-gson-java security update |
Debian DLA |
DLA-3100-1 | libgoogle-gson-java security update |
Debian DSA |
DSA-5227-1 | libgoogle-gson-java security update |
EUVD |
EUVD-2022-2402 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
Github GHSA |
GHSA-4jrv-ppp4-jm57 | Deserialization of Untrusted Data in Gson |
Ubuntu USN |
USN-6692-1 | Gson vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T03:32:46.390Z
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-25647
No data.
Status : Modified
Published: 2022-05-01T16:15:08.603
Modified: 2024-11-21T06:52:30.240
Link: CVE-2022-25647
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN