Skip to content

gson CVE-2022-25647 #2059

@antonmos

Description

@antonmos

Description

gson 2.8.5 has the aforementioned CVE. gson 2.8.9 fixes the issue
However, this comment says that gson cannot be updated until google/gson#1597 is fixed (it's not)

Seems like some workaround is necessary.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityPull requests that address a security vulnerability
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions