-
-
Notifications
You must be signed in to change notification settings - Fork 468
gson CVE-2022-25647 #2059
Copy link
Copy link
Closed
Labels
securityPull requests that address a security vulnerabilityPull requests that address a security vulnerability
Metadata
Metadata
Assignees
Labels
securityPull requests that address a security vulnerabilityPull requests that address a security vulnerability
Fields
Give feedbackNo fields configured for issues without a type.
Description
gson 2.8.5 has the aforementioned CVE. gson 2.8.9 fixes the issue
However, this comment says that gson cannot be updated until google/gson#1597 is fixed (it's not)
Seems like some workaround is necessary.