CVE-2022-3064
HIGH WAF: Medium
CVSS 7.5
Published: 2022-12-27
CWE-400
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
WAF Coverage Analysis
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| yaml_project | yaml | up to 2.2.4 |
References
- github.com (Patch, Third Party Advisory)
- github.com (Release Notes, Third Party Advisory)
- lists.debian.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- lists.fedoraproject.org
- pkg.go.dev (Patch, Vendor Advisory)