CVE-2022-25647
Deserialization of Untrusted Data in Gson
Description
The package com.google.code.gson:gson
before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace()
method in internal classes, which may lead to denial of service attacks.
Base CVSS
7.5
EPSS Score
1.59%
Introduced Version
2.2.3
Fix Available
2.8.9
Available Patches
Package
CVEs Fixed
Lines of Code Changed