Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25647

Опубликовано: 01 мая 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

A flaw was found in gson, which is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes. This issue may lead to availability attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2com.google.code.gson-gsonNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Will not fix
Red Hat AMQ Broker 7com.google.code.gson-gsonNot affected
Red Hat A-MQ Onlinecom.google.code.gson-gsonNot affected
Red Hat build of Debezium 1com.google.code.gson-gsonNot affected
Red Hat build of Quarkuscom.google.code.gson-gsonAffected
Red Hat Data Grid 8com.google.code.gson-gsonNot affected
Red Hat Fuse 7com.google.code.gson-gsonWill not fix
Red Hat Integration Camel K 1com.google.code.gson-gsonWill not fix
Red Hat Integration Camel Quarkus 1com.google.code.gson-gsonWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2080850com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson

EPSS

Процентиль: 83%
0.02149
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.7
nvd
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.7
debian
около 3 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to D ...

suse-cvrf
около 3 лет назад

Security update for google-gson

CVSS3: 7.7
github
около 3 лет назад

Deserialization of Untrusted Data in Gson

EPSS

Процентиль: 83%
0.02149
Низкий

7.5 High

CVSS3