CVE-2022-25647
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
HIGH · CVSS 7.7
EPSS 0.02873
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0