5
CVSSv2

CVE-2022-28948

Published: 19/05/2022 Updated: 28/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaml project yaml 3.0.0

netapp astra trident -

Vendor Advisories

Synopsis Moderate: Cryostat 211: new Cryostat on RHEL 8 container images Type/Severity Security Advisory: Moderate Topic New Cryostat 211 on RHEL 8 container images are now available Description New Cryostat 211 on RHEL 8 container images have been released, containing bug fixes and addressing the following security vulnerabilities: C ...
Debian Bug report logs - #1011338 golang-gopkg-yamlv3: CVE-2022-28948 - crash when attempting to deserialize invalid input Package: src:golang-gopkg-yamlv3; Maintainer for src:golang-gopkg-yamlv3 is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Neil Williams <codehelp@debianorg> Date: Fri ...
A flaw was found in the Unmarshal function in Go-Yaml The issue causes the program to crash when attempting to deserialize invalid input ...

Github Repositories

go vulnerability checker test

Go Vulnerability This repo contains a small test program which contains a vulnerability and can be used to test whether vulnerability checkers find it It can also be used as a perverse example to determine whether vulnerability checkers honour the module replace directive if present The small program uses the module gopkgin/yamlv3 at version v300-20200615113413-eeeca48fe7

GitHub profile (auto-updated every 6 hours)

Hi there πŸ‘‹ My name is ferhat, a curious mind and an avid reader Currently, I am working on @cloudflare R2 object storage πŸ‘· Check out what I'm currently working on ferhatelmas/algo - πŸ“š My solutions to algorithm problems on various websites (today) minio/minio-go - MinIO Go client SDK for S3 compatible object storage (1 week ago) zudochkin/awesome-newslette