CVE-2022-28948 is a high-severity vulnerability in Go-Yaml v3, affecting products like NetApp Astra Trident and NetApp Yaml. It allows an unauthenticated attacker to cause a denial of service (program crash) by providing invalid input during deserialization. While the CVSS score is 7.5, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:yaml_project:yaml:3.0.0:*:*:*:*:go:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:astra_trident:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-28948
Nov 14, 2023gopkg.in/yaml.v3 Denial of Service
May 20, 2022golang-gopkg-yaml: crash when attempting to deserialize invalid input
May 19, 2022An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
May 10, 2022