Skip to content

WS-2021-0419 (High) detected in gson-2.8.5.jar, gson-2.8.7.jar #57

@ws-on-ws

Description

@ws-on-ws

WS-2021-0419 - High Severity Vulnerability

Vulnerable Libraries - gson-2.8.5.jar, gson-2.8.7.jar

gson-2.8.5.jar

Gson JSON library

Library home page: https://github.com/google/gson

Path to dependency file: agents/wss-agent-api/pom.xml

Path to vulnerable library: .m2/repository/com/google/code/gson/gson/2.8.5/gson-2.8.5.jar

Dependency Hierarchy:

  • gson-2.8.5.jar (Vulnerable Library)
gson-2.8.7.jar

Library home page: https://github.com/google/gson

Path to dependency file: agents/wss-agent-client/pom.xml

Path to vulnerable library: .m2/repository/com/google/code/gson/gson/2.8.7/gson-2.8.7.jar,.m2/repository/com/google/code/gson/gson/2.8.7/gson-2.8.7.jar,.m2/repository/com/google/code/gson/gson/2.8.7/gson-2.8.7.jar,/home/wss-scanner/.m2/repository/com/google/code/gson/gson/2.8.7/gson-2.8.7.jar

Dependency Hierarchy:

  • gson-2.8.7.jar (Vulnerable Library)

Found in base branch: master

Vulnerability Details

Denial of Service vulnerability was discovered in gson before 2.8.9 via the writeReplace() method.

Publish Date: 2021-10-11

URL: WS-2021-0419

CVSS 3 Score Details (7.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: N/A
    • Attack Complexity: N/A
    • Privileges Required: N/A
    • User Interaction: N/A
    • Scope: N/A
  • Impact Metrics:
    • Confidentiality Impact: N/A
    • Integrity Impact: N/A
    • Availability Impact: N/A

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/google/gson/releases/tag/gson-parent-2.8.9

Release Date: 2021-10-11

Fix Resolution: com.google.code.gson:gson:2.8.9

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions