Google Gson Vulnerability CVE-2022-25647
Issue date: 21-09-2022Affects versions: 15.1, 14.7, 13.4
Security Issue ID
SECURITY-328
Affected Product Version(s)
15.1.0, 14.7.8, 13.4.18, and all previous versions
Severity
Medium
Description
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. An application would de-serialize untrusted data without sufficiently verifying that the resulting data will be valid, letting the attacker to control the state or the flow of the execution. This can lead to a denial of service or even the execution of arbitrary code.
The fix is available in version 2.9.0
Instructions
Customers are recommended to upgrade to the latest version. As of the time of writing, 15.1.1, 14.7.9 or 13.4.19