Lucene search

K
osvGoogleOSV:CVE-2022-25647
HistoryMay 01, 2022 - 4:15 p.m.

CVE-2022-25647

2022-05-0116:15:08
Google
osv.dev
11

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

65.0%

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.