Related Vulnerabilities: CVE-2022-25647  

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Description

The MITRE CVE dictionary describes this issue as:

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Additional Information

  • Bugzilla 2080850: CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
  • CWE-502: Deserialization of Untrusted Data
  • FAQ: Frequently asked questions about CVE-2022-25647