Mageia 2022-0340: google-gson security update

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. (CVE-2022-25647) References:

This article has been indexed from LinuxSecurity.com – Hybrid RSS

Read the original article:

Liked it? Take a second to support IT Security News on Patreon!
Become a patron at Patreon!