The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3001-1 | libgoogle-gson-java security update |
Debian DLA |
DLA-3100-1 | libgoogle-gson-java security update |
Debian DSA |
DSA-5227-1 | libgoogle-gson-java security update |
EUVD |
EUVD-2022-2402 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
Github GHSA |
GHSA-4jrv-ppp4-jm57 | Deserialization of Untrusted Data in Gson |
Ubuntu USN |
USN-6692-1 | Gson vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T03:32:46.390Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25647
No data.
Status : Modified
Published: 2022-05-01T16:15:08.603
Modified: 2024-11-21T06:52:30.240
Link: CVE-2022-25647
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN