CVE-2022-25647

HIGH

Google Gson < 2.8.9 - Insecure Deserialization

Title source: rule

Description

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Scores

CVSS v3 7.7
EPSS 0.0208
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (15)

google/gson < 2.8.9
debian/debian_linux
debian/debian_linux
debian/debian_linux
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
oracle/financial_services_crime_and_compliance_management_studio
oracle/financial_services_crime_and_compliance_management_studio
oracle/graalvm
oracle/graalvm
oracle/graalvm
oracle/retail_order_broker
oracle/retail_order_broker
com.google.code.gson/gson < 2.8.9Maven

Timeline

Published May 01, 2022
Tracked Since Feb 18, 2026