Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.google.guava/guava
  4. ›
  5. CVE-2018-10237

CVE-2018-10237: Deserialization of Untrusted Data

April 26, 2018 (updated June 12, 2019)

Unbounded memory allocation allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

References

  • github.com/google/guava/wiki/CVE-2018-10237
  • groups.google.com/forum/
  • nvd.nist.gov/vuln/detail/CVE-2018-10237

Code Behaviors & Features

Detect and mitigate CVE-2018-10237 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 11.0-rc1 before 24.1.1

Fixed versions

  • 24.1.1-jre
  • 24.1.1-android

Solution

Upgrade to the fixed version

Impact 5.9 MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

maven/com.google.guava/guava/CVE-2018-10237.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:02 +0000.