Skip to content
This repository has been archived by the owner on Sep 26, 2024. It is now read-only.

CVE-2022-25647 (High) detected in gson-2.7.jar #40

Open
mend-bolt-for-github bot opened this issue May 5, 2022 · 0 comments
Open

CVE-2022-25647 (High) detected in gson-2.7.jar #40

mend-bolt-for-github bot opened this issue May 5, 2022 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link

mend-bolt-for-github bot commented May 5, 2022

CVE-2022-25647 - High Severity Vulnerability

Vulnerable Library - gson-2.7.jar

Gson JSON library

Library home page: https://github.com/google/gson

Path to dependency file: /cap-core/pom.xml

Path to vulnerable library: /r/.m2/repository/com/google/code/gson/gson/2.7/gson-2.7.jar

Dependency Hierarchy:

  • gson-2.7.jar (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Publish Date: 2022-05-01

URL: CVE-2022-25647

CVSS 3 Score Details (7.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25647`

Release Date: 2022-05-01

Fix Resolution: 2.8.9


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label May 5, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2022-25647 (High) detected in gson-2.7.jar CVE-2022-25647 (High) detected in com-google-gson-RELEASE100.jar Mar 11, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2022-25647 (High) detected in com-google-gson-RELEASE100.jar CVE-2022-25647 (High) detected in gson-2.7.jar Mar 17, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants