The package com.google.code.gson:gson before 2.8.9 are vulnerable to
Deserialization of Untrusted Data via the writeReplace() method in
internal classes, which may lead to DoS attacks. (CVE-2022-25647)
- https://bugs.mageia.org/show_bug.cgi?id=30541
-
- https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html
- https://lists.debian.org/debian-security-announce/2022/msg00196.html
- https://www.cve.org/CVERecord?id=CVE-2022-25647
- 8/core/google-gson-2.8.6-1.1.mga8
Get the latest Linux and open source security news straight to your inbox.