sirupsen / logrus

Structured, pluggable logging for Go.
MIT License
24.8k stars 2.27k forks source link

New CVE was discovered CVE-2022-28948 #1336

Closed izhakmo closed 2 years ago

izhakmo commented 2 years ago

https://nvd.nist.gov/vuln/detail/CVE-2022-28948

https://github.com/go-yaml/yaml/releases/tag/v3.0.1

link to issue : https://github.com/go-yaml/yaml/issues/666

chkp-rigor commented 2 years ago

Hi @dgsb @sirupsen, It's a security issue (even if potential) that code scanners show. Can you please prioritize this PR? Thanks in advance! And thank you for the logrus!