Junglewise Threat Intelligence

CVE-2022-25647: Google Gson deserialization of untrusted data in internal classes

CVE-2022-25647 · Severity: high · CVSS 7.7 · Published 2022-05-03

Vendors: Maven, Google.

Executive brief

Google Gson is a popular Java library used to convert Java objects into JSON format and vice versa. A security flaw in versions prior to 2.8.9 allows an attacker to send specially crafted data that, when processed, can crash the application or cause a denial of service. This could disrupt business operations by making affected services unavailable to legitimate users.

Technical details

Google Gson before version 2.8.9 is vulnerable to the deserialization of untrusted data (CWE-502). The vulnerability exists within the writeReplace() method of internal classes, which can be abused during Java serialization/deserialization processes. An attacker can exploit this by providing malicious input to an application that uses Gson to deserialize untrusted data. While the primary impact is a denial of service (DoS), the CVSS metrics also suggest potential low-impact confidentiality and high-impact integrity concerns depending on the implementation environment. The issue was addressed in version 2.8.9 by preventing Java deserialization of these internal classes.

Affected products

  • Google Gson < 2.8.9

Timeline

  • 2021-10-13: patched: Fix merged into master branch
  • 2022-05-01: advisory: NVD published CVE-2022-25647
  • 2022-05-03: advisory: GitHub published GHSA-4jrv-ppp4-jm57

References