CVE-2022-25647
published 2022-05-01CVE-2022-25647: The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
12.23%
95.7th percentile
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | crucible | — | — |
| atlassian | fisheye | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgoogle-gson-java | < libgoogle-gson-java 2.9.0-1 (bookworm) | libgoogle-gson-java 2.9.0-1 (bookworm) |
| gson | >= 2.2.3 < 2.8.9 | 2.8.9 | |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | financial_services_crime_and_compliance_management_studio | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | retail_order_broker | — | — |
| oracle | retail_order_broker | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Deserialization of Untrusted Data in Gson
ghsa·2022-05-03
CVE-2022-25647 [HIGH] CWE-502 Deserialization of Untrusted Data in Gson
Deserialization of Untrusted Data in Gson
The package `com.google.code.gson:gson` before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the `writeReplace()` method in internal classes, which may lead to denial of service attacks.
OSV
Deserialization of Untrusted Data in Gson
osv·2022-05-03
CVE-2022-25647 [HIGH] Deserialization of Untrusted Data in Gson
Deserialization of Untrusted Data in Gson
The package `com.google.code.gson:gson` before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the `writeReplace()` method in internal classes, which may lead to denial of service attacks.
OSV
CVE-2022-25647: The package com
osv·2022-05-01·CVSS 7.5
CVE-2022-25647 [HIGH] CVE-2022-25647: The package com
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
Ubuntu
Gson vulnerability
vendor_ubuntu·2024-03-12
CVE-2022-25647 Gson vulnerability
Title: Gson vulnerability
Summary: Gson could be made to crash if it opened a specially crafted
file.
It was discovered that Gson incorrectly handled deserialization of untrusted
input data. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use this issue
to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Analytics Risk Matrix: Installation (Google Gson) — CVE-2022-25647
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Analytics Risk Matrix: Installation (Google Gson) — CVE-2022-25647
Oracle Oracle Analytics Risk Matrix: Installation (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Google Gson) — CVE-2022-25647
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Google Gson) — CVE-2022-25647
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Google Gson) — CVE-2022-25647
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: General (Google Gson) — CVE-2022-25647
Oracle Oracle Fusion Middleware Risk Matrix: General (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Google Gson) — CVE-2022-25647
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Google Gson) — CVE-2022-25647
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (Google Gson) — CVE-2022-25647
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2022-25647 [HIGH] Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (Google Gson) — CVE-2022-25647
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Google Gson) — CVE-2022-25647
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Communications Risk Matrix: Signaling (Google Gson) — CVE-2022-25647
Oracle Oracle Communications Risk Matrix: Signaling (Google Gson) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Google GSON) — CVE-2022-25647
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2022-25647 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Google GSON) — CVE-2022-25647
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Google GSON) vulnerability
CVE: CVE-2022-25647
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Red Hat
com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
vendor_redhat·2022-05-01·CVSS 7.7
CVE-2022-25647 [HIGH] CWE-502 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
A flaw was found in gson, which is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes. This issue may lead to availability attacks.
Package: com.google.code.gson-gson (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Will not fix
Package: com.google.code.gson-gson (Red Hat AMQ Broker 7) - Not affected
Package: com.google.code.gson-gson (Red Hat A-MQ Online) - Not affected
Package: com.google.co
Debian
CVE-2022-25647: libgoogle-gson-java - The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserializa...
vendor_debian·2022·CVSS 7.7
CVE-2022-25647 [HIGH] CVE-2022-25647: libgoogle-gson-java - The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserializa...
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
Scope: local
bookworm: resolved (fixed in 2.9.0-1)
bullseye: resolved (fixed in 2.8.6-1+deb11u1)
forky: resolved (fixed in 2.9.0-1)
sid: resolved (fixed in 2.9.0-1)
trixie: resolved (fixed in 2.9.0-1)
Atlassian
CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
vendor_atlassian·CVSS 4.8
CVE-2022-25647 [HIGH] CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
CVE: CVE-2022-25647
Affected products: Crucible, Fisheye
No detection rules found.
No public exploits indexed.
Checkpoint
25th September – Threat Intelligence Report
blogs_checkpoint·2023-09-25
CVE-2023-41991 25th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th September, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Monti ransomware gang has claimed responsibility for a cyber-attack on New Zealand’s third-largest university, Auckland University of Technology. The threat actors claim to have stolen 60GB of data, giving the victim a deadline of October 9 th to pay a ransom.
Check Point Threat Emulation provides protection against
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://github.com/google/gson/pull/1991https://github.com/google/gson/pull/1991/commitshttps://lists.debian.org/debian-lts-announce/2022/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00009.htmlhttps://security.netapp.com/advisory/ntap-20220901-0009/https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327https://www.debian.org/security/2022/dsa-5227https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/google/gson/pull/1991https://github.com/google/gson/pull/1991/commitshttps://lists.debian.org/debian-lts-announce/2022/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00009.htmlhttps://security.netapp.com/advisory/ntap-20220901-0009/https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327https://www.debian.org/security/2022/dsa-5227https://www.oracle.com/security-alerts/cpujul2022.html
2022-05-01
Published