GHSA-4jrv-ppp4-jm57
The package com.google.code.gson:gson before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to denial of service attacks.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2022-25647, https://github.com/google/gson/pull/1991, https://github.com/google/gson/pull/1991/commits, https://github.com/google/gson, https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html, https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html, https://security.netapp.com/advisory/ntap-20220901-0009, https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327, https://www.debian.org/security/2022/dsa-5227, https://www.oracle.com/security-alerts/cpujul2022.html
