The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openjdk13Upgrade openjdk11Upgrade openjdk15Upgrade openjdk17 | Aug 22, 2024 | May 1, 2022 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Nov 14, 2024 | Oct 17, 2023 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | May 21, 2024 |
| Debian | — | Upgrade libgoogle-gson-java | May 16, 2022 | May 1, 2022 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 29, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34890864 for version 14.1.1.0.0. | Jan 17, 2023 | May 1, 2022 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | May 1, 2022 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | May 1, 2022 |
| Suse | — | Upgrade google-gsonUpgrade google-gson-javadoc | Oct 26, 2022 | May 1, 2022 |
| Ubuntu | — | Upgrade libgoogle-gson-javaUpgrade libgoogle-gson-java (Ubuntu Pro) | Mar 13, 2024 | May 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub