CVE-2022-25647
high · 7.7The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
7.7
CVSS
12.2%
EPSS (exploit prob.)
96th
EPSS percentile
2022-05-01
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gson | >= 2.2.3, < 2.8.9 | |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
| oracle | graalvm | 20.3.6 |
| oracle | graalvm | 21.3.2 |
| oracle | graalvm | 22.1.0 |
| oracle | retail_order_broker | 18.0 |
| oracle | retail_order_broker | 19.1 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/google/gson/pull/1991
- https://github.com/google/gson/pull/1991/commits
- https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html
- https://security.netapp.com/advisory/ntap-20220901-0009/
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327
- https://www.debian.org/security/2022/dsa-5227
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/google/gson/pull/1991
- https://github.com/google/gson/pull/1991/commits
- https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html
- https://security.netapp.com/advisory/ntap-20220901-0009/
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327
- https://www.debian.org/security/2022/dsa-5227
- https://www.oracle.com/security-alerts/cpujul2022.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-25647