Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug google-http-client-gson-1.42.0.jar HEIGH Vulnerability #1674

Closed
genesiscastillo opened this issue Jun 16, 2022 · 4 comments
Closed

Bug google-http-client-gson-1.42.0.jar HEIGH Vulnerability #1674

genesiscastillo opened this issue Jun 16, 2022 · 4 comments
Labels
🚨 This issue needs some love. triage me I really want to be triaged.

Comments

@genesiscastillo genesiscastillo changed the title Bug google-http-client-gson-1.42.0.jar MEDIUM Vulnerability Bug google-http-client-gson-1.42.0.jar HEIGH Vulnerability Jun 16, 2022
@yoshi-automation yoshi-automation added the triage me I really want to be triaged. label Jun 17, 2022
@Capstan
Copy link
Contributor

Capstan commented Jun 19, 2022

The complaint in the link is that Gson version before 2.8.9 are vulnerable. Head is currently importing 2.9.0 (#1582), and the first fixed version was imported in #1492, and is available in v1.42.0.

@Capstan
Copy link
Contributor

Capstan commented Jun 19, 2022

That CPE is weird. There is no version of https://github.com/google/gson that is v1.42.0. And that CPE isn't pointing at google-http-client-gson which does have a v1.42.0, but that version doesn't have the issue specified, because it requires a later version of Gson.

@Capstan
Copy link
Contributor

Capstan commented Jun 19, 2022

I guess NIST assumes since all Gson versions <2.8.9 are vulnerable, a mythical Gson version 1.42.0 would also be vulnerable. That said, the CPE tag does not apply to this repo, and this repo pins a non-vulnerable version of Gson since v1.42.0.

Now that said, I wonder if this should show up in the https://github.com/googleapis/google-http-java-client/security/advisories section. 🤔

@yoshi-automation yoshi-automation added the 🚨 This issue needs some love. label Jun 21, 2022
@meltsufin
Copy link
Member

This repo uses GSON 2.9.0. Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🚨 This issue needs some love. triage me I really want to be triaged.
Projects
None yet
Development

No branches or pull requests

4 participants