GHSA-4jrv-ppp4-jm57
HIGHCVE-2022-25647The package com.google.code.gson:gson before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to denial of service attacks.
- Affected
- < 2.8.9
- Fixed in
- 2.8.9
- Weakness
- CWE-502
- Published
- 2022-05-03
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference