We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Gson JSON library
Library home page: https://github.com/google/gson
Path to dependency file: /jetty-infinispan/infinispan-remote-query/pom.xml
Path to vulnerable library: /jetty-infinispan/infinispan-remote-query/pom.xml,/tests/test-sessions/test-infinispan-sessions/pom.xml
Dependency Hierarchy:
Path to dependency file: /tests/test-sessions/test-gcloud-sessions/pom.xml
Path to vulnerable library: /tests/test-sessions/test-gcloud-sessions/pom.xml,/jetty-gcloud/jetty-gcloud-session-manager/pom.xml
Found in HEAD commit: f8dcdb434f8449805a9ff352d32b114dfe9bf1dd
Found in base branch: master
Denial of Service vulnerability was discovered in gson before 2.8.9 via the writeReplace() method.
Publish Date: 2021-10-11
URL: WS-2021-0419
Base Score Metrics:
Type: Upgrade version
Release Date: 2021-10-11
Fix Resolution (com.google.code.gson:gson): 2.8.9
Direct dependency fix Resolution (org.infinispan:infinispan-remote-query-client): 9.4.17.Final
Direct dependency fix Resolution (com.google.cloud:google-cloud-datastore): 2.21.2
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered:
No branches or pull requests
WS-2021-0419 - High Severity Vulnerability
gson-2.8.1.jar
Gson JSON library
Library home page: https://github.com/google/gson
Path to dependency file: /jetty-infinispan/infinispan-remote-query/pom.xml
Path to vulnerable library: /jetty-infinispan/infinispan-remote-query/pom.xml,/tests/test-sessions/test-infinispan-sessions/pom.xml
Dependency Hierarchy:
gson-2.7.jar
Gson JSON library
Library home page: https://github.com/google/gson
Path to dependency file: /tests/test-sessions/test-gcloud-sessions/pom.xml
Path to vulnerable library: /tests/test-sessions/test-gcloud-sessions/pom.xml,/jetty-gcloud/jetty-gcloud-session-manager/pom.xml
Dependency Hierarchy:
Found in HEAD commit: f8dcdb434f8449805a9ff352d32b114dfe9bf1dd
Found in base branch: master
Denial of Service vulnerability was discovered in gson before 2.8.9 via the writeReplace() method.
Publish Date: 2021-10-11
URL: WS-2021-0419
Base Score Metrics:
Type: Upgrade version
Release Date: 2021-10-11
Fix Resolution (com.google.code.gson:gson): 2.8.9
Direct dependency fix Resolution (org.infinispan:infinispan-remote-query-client): 9.4.17.Final
Fix Resolution (com.google.code.gson:gson): 2.8.9
Direct dependency fix Resolution (com.google.cloud:google-cloud-datastore): 2.21.2
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: