Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SDK impacted by CVE-2022-25647 #1237

Open
5 tasks done
ZOlbrys opened this issue Mar 25, 2024 · 0 comments
Open
5 tasks done

SDK impacted by CVE-2022-25647 #1237

ZOlbrys opened this issue Mar 25, 2024 · 0 comments

Comments

@ZOlbrys
Copy link

ZOlbrys commented Mar 25, 2024

Checklist before submitting a bug report

Java version

17

Android version

API 34

Android SDK version

16.0.0

Installation platform & version

AGP 8.3.0

Package

Gaming Services

Goals

The supplied version of gson in the FB SDK has a security issue (CVE-2022-25647).

Expected results

A newer version of gson without CVE-2022-25647 should be used

Actual results

....com.facebook.android:[email protected] › 
com.facebook.android:[email protected] › 
com.google.code.gson:[email protected]

Gson 2.8.8 is added via the gamingservices SDK, which has a security vulnerability, see https://www.cve.org/CVERecord?id=CVE-2022-25647

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant