CVE-2022-28948

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
19/05/2022
Last modified:
28/10/2022

Description

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yaml_project:yaml:3.0.0:*:*:*:*:go:*:*
cpe:2.3:a:netapp:astra_trident:-:*:*:*:*:*:*:*