PT-2022-19325 · Go-Yaml+3 · Go-Yaml+3
Bradleyjkemp
·
Published
2022-05-19
·
Updated
2026-01-30
·
CVE-2022-28948
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Go-Yaml version v3
Description
An issue in the Unmarshal function causes the program to crash or panic when attempting to deserialize invalid input.
Recommendations
For Go-Yaml version v3, consider validating input data before attempting to deserialize it to prevent the program from crashing or panicking. As a temporary workaround, consider adding error handling to the Unmarshal function to manage invalid input gracefully. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Go-Yaml
Suse