DSA-5227-1 libgoogle-gson-java -- libgoogle-gson-javaID: oval:org.secpod.oval:def:610114 | Date: (C)2022-09-09 (M)2023-02-13 |
Class: PATCH | Family: unix |
It was discovered that Gson, a Java library that can be used to convert Java Objects into their JSON representations and vice versa, was vulnerable to a de- serialization flaw. An application would de-serialize untrusted data without sufficiently verifying that the resulting data will be valid, letting the attacker to control the state or the flow of the execution. This can lead to a denial of service or even the execution of arbitrary code.
Product: |
libgoogle-gson-java |