HIGH7.5
GHSA-hp87-p4gw-j4gq
gopkg.in/yaml.v3 Denial of Service
Quick fix
GHSA-hp87-p4gw-j4gq — gopkg.in/yaml.v3: upgrade to the fixed version with the command below.
go get gopkg.in/yaml.v3@v3.0.1Details
An issue in the Unmarshal function in Go-Yaml v3 can cause a program to panic when attempting to deserialize invalid input.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-28948[ADVISORY]
- https://github.com/go-yaml/yaml/issues/665[WEB]
- https://github.com/go-yaml/yaml/issues/666[WEB]
- https://github.com/go-yaml/yaml/commit/8f96da9f5d5eff988554c1aae1784627c4bf6754[WEB]
- https://github.com/go-yaml/yaml/commit/f6f7691b1fdeb513f56608cd2c32c51f8194bf51[WEB]
- https://github.com/go-yaml/yaml[PACKAGE]
- https://security.netapp.com/advisory/ntap-20220923-0006[WEB]