Skip to main content

CVE-2022-28948

CVE Details

Visit the official vulnerability details page for CVE-2022-28948 to learn more.

Initial Publication

10/25/2024

Last Update

10/25/2024

Third Party Dependency

gopkg.in/yaml.v3

NIST CVE Summary

An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

CVE Severity

7.5

Our Official Summary

This CVE is non impacting as the impacting symbol and/or function is not used in the product.

Status

Ongoing

Affected Products & Versions

VersionPalette EnterprisePalette Enterprise AirgapVerteXVerteX Airgap
4.5.11ImpactedImpactedNo ImpactImpacted
4.5.10ImpactedImpactedNo ImpactImpacted
4.5.8ImpactedImpactedNo ImpactImpacted
4.5.5ImpactedImpactedNo ImpactImpacted
4.5.4ImpactedImpactedNo ImpactImpacted
4.4.20ImpactedImpactedNo ImpactImpacted

Revision History

DateRevision
11/30/2024Advisory is now impacting.
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10, 4.5.11
11/15/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8, 4.4.20 to 4.5.4, 4.5.5, 4.5.8, 4.4.20, 4.5.10
11/13/2024Impacted versions changed from 4.5.4, 4.5.5, 4.5.8 to 4.5.4, 4.5.5, 4.5.8, 4.4.20
11/10/2024Impacted versions changed from 4.5.4, 4.5.5 to 4.5.4, 4.5.5, 4.5.8
10/27/2024Impacted versions changed from 4.5.4 to 4.5.4, 4.5.5