CVE-2022-28948Deserialization of Untrusted Data in Yaml.v3

Severity
7.5HIGHNVD
EPSS
1.5%
top 18.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateAug 22

Description

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Gogopkg.in/yaml.v3< 3.0.1+1
debiandebian/golang-gopkg-yaml.v3< golang-gopkg-yaml.v3 3.0.1-1 (bookworm)

Patches

🔴Vulnerability Details

4
OSV
Panic in gopkg.in/yaml.v32022-08-22
OSV
gopkg.in/yaml.v3 Denial of Service2022-05-20
GHSA
gopkg.in/yaml.v3 Denial of Service2022-05-20
OSV
CVE-2022-28948: An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input2022-05-19

📋Vendor Advisories

3
Red Hat
golang-gopkg-yaml: crash when attempting to deserialize invalid input2022-05-19
Microsoft
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.2022-05-10
Debian
CVE-2022-28948: golang-gopkg-yaml.v3 - An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash whe...2022
CVE-2022-28948 — Deserialization of Untrusted Data | cvebase