Lucene search

K
broadcomBroadcom Security ResponseBSNSA22450
HistoryAug 29, 2023 - 12:00 a.m.

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization

2023-08-2900:00:00
Broadcom Security Response
support.broadcom.com
19
vulnerability
deserialization
untrusted data
writereplace() method
dos attacks
software

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

65.0%

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Affected configurations

Vulners
Node
broadcombrocade_sannavRange<2.2.0
OR
broadcombrocade_sannavRange<2.2.2a
CPENameOperatorVersion
brocade sannavlt2.2.0
brocade sannavlt2.2.2a