Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2023-09014

Опубликовано: 01 мая 2022
Источник: fstec
CVSS3: 7.7
CVSS2: 7.3
EPSS Низкий

Описание

Уязвимость пакета com.google.code.gson:gson библиотеки Gson связана с недостатками механизма десериализации. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить атаку типа «отказ в обслуживании» (DoS)

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
Novell Inc.
Oracle Corp.
NetApp Inc.
АО "НППКТ"
Google Inc.

Наименование ПО

Red Hat JBoss Fuse
Debian GNU/Linux
Red Hat Single Sign-On
openSUSE Tumbleweed
Oracle Retail Order Broker
Red Hat JBoss Data Grid
A-MQ Clients
Suse Linux Enterprise Server
Red Hat build of Quarkus
Red Hat Integration Camel K
Red Hat Integration Service Registry
OpenSUSE Leap
Red Hat Integration Camel Quarkus
Red Hat Data Grid
Red Hat JBoss Enterprise Application Platform Expansion Pack
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Proxy
Suse Linux Enterprise Desktop
SUSE Enterprise Storage
SUSE Manager Server
SUSE Linux Enterprise Module for Development Tools
SUSE Manager Retail Branch Server
Active IQ Unified Manager for Microsoft Windows
Active IQ Unified Manager for VMware vSphere
Red Hat OpenShift Container Platform
Red Hat Integration Change Data Capture
Red Hat AMQ Online
GraalVM Enterprise Edition
Decision Manager
Oracle Financial Services Crime and Compliance Management Studio
ОСОН ОСнова Оnyx
Red Hat JBoss A-MQ
Red Hat JBoss Enterprise Application Platform
Management Service for Element Software and NetApp Hci
Active IQ Unified Manager for Linux
OpenShift Developer Tools and Services for OCP
Red Hat Process Automation Manager
Logging subsystem for Red Hat OpenShift
Red Hat AMQ Streams
Cryostat
Red Hat build of Eclipse Vert.x
Red Hat Integration Data Virtualisation Operator
Red Hat support for Spring Boot
SUSE Manager Server Module
Gson

Версия ПО

7 (Red Hat JBoss Fuse)
10 (Debian GNU/Linux)
7 (Red Hat Single Sign-On)
- (openSUSE Tumbleweed)
18.0 (Oracle Retail Order Broker)
7 (Red Hat JBoss Data Grid)
2 (A-MQ Clients)
19.1 (Oracle Retail Order Broker)
15 SP 3 (Suse Linux Enterprise Server)
- (Red Hat build of Quarkus)
- (Red Hat Integration Camel K)
- (Red Hat Integration Service Registry)
15.3 (OpenSUSE Leap)
- (Red Hat Integration Camel Quarkus)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
8 (Red Hat Data Grid)
- (Red Hat JBoss Enterprise Application Platform Expansion Pack)
15.4 (OpenSUSE Leap)
15 SP3 (SUSE Linux Enterprise High Performance Computing)
15 SP3 (SUSE Linux Enterprise Server for SAP Applications)
4.2 (SUSE Manager Proxy)
15 SP3 (Suse Linux Enterprise Desktop)
7 (SUSE Enterprise Storage)
15 SP2 (SUSE Linux Enterprise Server for SAP Applications)
4.1 (SUSE Manager Server)
4.1 (SUSE Manager Proxy)
15 SP2-ESPOS (SUSE Linux Enterprise High Performance Computing)
15 SP2-LTSS (SUSE Linux Enterprise High Performance Computing)
15 SP3 (SUSE Linux Enterprise Module for Development Tools)
4.1 (SUSE Manager Retail Branch Server)
- (Active IQ Unified Manager for Microsoft Windows)
- (Active IQ Unified Manager for VMware vSphere)
15 SP4 (Suse Linux Enterprise Server)
4 (Red Hat OpenShift Container Platform)
- (Red Hat Integration Change Data Capture)
15 SP4 (Suse Linux Enterprise Desktop)
15 SP2-BCL (Suse Linux Enterprise Server)
15 SP4 (SUSE Linux Enterprise Server for SAP Applications)
4.2 (SUSE Manager Retail Branch Server)
- (Red Hat AMQ Online)
15 SP2-LTSS (Suse Linux Enterprise Server)
4.3 (SUSE Manager Retail Branch Server)
4.3 (SUSE Manager Proxy)
4.3 (SUSE Manager Server)
15 SP4 (SUSE Linux Enterprise High Performance Computing)
7.1 (SUSE Enterprise Storage)
15 SP4 (SUSE Linux Enterprise Module for Development Tools)
22.1.0 (GraalVM Enterprise Edition)
21.3.2 (GraalVM Enterprise Edition)
20.3.6 (GraalVM Enterprise Edition)
7 (Decision Manager)
8.0.8.2.0 (Oracle Financial Services Crime and Compliance Management Studio)
8.0.8.3.0 (Oracle Financial Services Crime and Compliance Management Studio)
до 2.6 (ОСОН ОСнова Оnyx)
15 SP5 (SUSE Linux Enterprise Server for SAP Applications)
15 SP5 (Suse Linux Enterprise Server)
15 SP5 (Suse Linux Enterprise Desktop)
7 (Red Hat JBoss A-MQ)
15 SP5 (SUSE Linux Enterprise High Performance Computing)
15 SP5 (SUSE Linux Enterprise Module for Development Tools)
7 (Red Hat JBoss Enterprise Application Platform)
- (Management Service for Element Software and NetApp Hci)
- (Active IQ Unified Manager for Linux)
6 (Red Hat JBoss Enterprise Application Platform)
4.13 (OpenShift Developer Tools and Services for OCP)
7.4 for RHEL 9 (Red Hat JBoss Enterprise Application Platform)
2.3.0 GA (Red Hat Integration Service Registry)
7.13.0 (Red Hat Process Automation Manager)
- (Logging subsystem for Red Hat OpenShift)
2.2.0 (Red Hat AMQ Streams)
2 on RHEL 8 (Cryostat)
4.2.7 (Red Hat build of Eclipse Vert.x)
- (Red Hat Integration Data Virtualisation Operator)
- (Red Hat support for Spring Boot)
4.1 (SUSE Manager Server Module)
4.2 (SUSE Manager Server Module)
4.3 (SUSE Manager Server Module)
от 2.2.3 до 2.8.9 (Gson)

Тип ПО

Прикладное ПО информационных систем
Операционная система
Сетевое программное средство
Сетевое средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 10
Novell Inc. openSUSE Tumbleweed -
Novell Inc. Suse Linux Enterprise Server 15 SP 3
Novell Inc. OpenSUSE Leap 15.3
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
Novell Inc. OpenSUSE Leap 15.4
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP3
Novell Inc. Suse Linux Enterprise Desktop 15 SP3
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP2
Novell Inc. Suse Linux Enterprise Server 15 SP4
Novell Inc. Suse Linux Enterprise Desktop 15 SP4
Novell Inc. Suse Linux Enterprise Server 15 SP2-BCL
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP4
Novell Inc. Suse Linux Enterprise Server 15 SP2-LTSS
АО "НППКТ" ОСОН ОСнова Оnyx до 2.6
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP5
Novell Inc. Suse Linux Enterprise Server 15 SP5
Novell Inc. Suse Linux Enterprise Desktop 15 SP5

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,3)
Высокий уровень опасности (базовая оценка CVSS 3.0 составляет 7,7)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для программных продуктов Google Inc.:
https://github.com/google/gson/pull/1991
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2022-25647
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2022-25647
Для программных продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2022-25647.html
Для программных продуктов NetApp Inc.:
https://security.netapp.com/advisory/ntap-20220901-0009/
Для программных продуктов Oracle Corp.:
https://www.oracle.com/security-alerts/cpujul2022.html
Для ОСОН ОСнова Оnyx:
Обновление программного обеспечения libgoogle-gson-java до версии 2.8.5-3+deb10u1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 83%
0.02149
Низкий

7.7 High

CVSS3

7.3 High

CVSS2

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.5
redhat
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.7
nvd
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.7
debian
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to D ...

suse-cvrf
около 3 лет назад

Security update for google-gson

EPSS

Процентиль: 83%
0.02149
Низкий

7.7 High

CVSS3

7.3 High

CVSS2