Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
References
Link | Resource |
---|---|
https://github.com/go-yaml/yaml/releases/tag/v2.2.4 | Release Notes Third Party Advisory |
https://pkg.go.dev/vuln/GO-2022-0956 | Patch Vendor Advisory |
https://github.com/go-yaml/yaml/commit/f221b8435cfb71e54062f6c6e99e9ade30b124d5 | Patch Third Party Advisory |
Configurations
Information
Published : 2022-12-27 14:15
Updated : 2023-01-06 05:51
NVD link : CVE-2022-3064
Mitre link : CVE-2022-3064
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
yaml_project
- yaml