facebook-android-sdk icon indicating copy to clipboard operation
facebook-android-sdk copied to clipboard

SDK impacted by CVE-2022-25647

Open ZOlbrys opened this issue 3 months ago • 0 comments

Checklist before submitting a bug report

Java version

17

Android version

API 34

Android SDK version

16.0.0

Installation platform & version

AGP 8.3.0

Package

Gaming Services

Goals

The supplied version of gson in the FB SDK has a security issue (CVE-2022-25647).

Expected results

A newer version of gson without CVE-2022-25647 should be used

Actual results

....com.facebook.android:[email protected] › 
com.facebook.android:[email protected] › 
com.google.code.gson:[email protected]

Gson 2.8.8 is added via the gamingservices SDK, which has a security vulnerability, see https://www.cve.org/CVERecord?id=CVE-2022-25647

ZOlbrys avatar Mar 25 '24 12:03 ZOlbrys