google / gnostic

A compiler for APIs described by the OpenAPI Specification with plugins for code generation and other API support tasks.
Apache License 2.0
2.08k stars 247 forks source link

We are unable to detect the CVE-2022-28948 vulnerability through our vulnerability scanning. #398

Open qilitang opened 1 year ago

qilitang commented 1 year ago

We are unable to detect the CVE-2022-28948 vulnerability through our vulnerability scanning.

gopkg.in/yaml.v3 v3.0.0-202 101051613 48-2e7810 8cf5f8

An issue in the Unmarshal f unction in Go-Yaml v3 caus es the program to crash wh en attempting to deserialize invalid input.