CVE-2022-3064

Aliases:GHSA-6q6q-88xp-6f2rGO-2022-0956RHSA-2023:1014RHSA-2024:10759RHSA-2024:10784RHSA-2024:4443DEBIAN-CVE-2022-3064CGA-4xgc-43g4-2cxmCGA-p3x4-wcg9-3r2pCGA-7jwf-r2mg-2rp8CGA-j8mf-vp6m-2h5qCGA-qwxq-qw7p-c6fcCGA-rw98-frw8-r9jqCGA-w98q-78xj-x4g8CGA-wg56-cqq3-mrqx
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 27 Dec 2022, 21:17
Last modified:14 Apr 2025, 17:05

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.7% LOW
2% probability -0.52%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Dec 2022, 21:17
Published
Vulnerability first disclosed
14 Apr 2025, 17:05
Last Modified
Vulnerability information updated

Description

Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.70% Percentile: 76%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguarddex-k8s-authenticator

    < 1.4.0-r34

  • chainguardk3d

    < 5.6.0-r11

  • chainguardk3d-proxy

    < 5.6.0-r11

  • chainguardk3d-tools

    < 5.6.0-r11

  • wolfik3d

    < 5.6.0-r11

  • wolfik3d-proxy

    < 5.6.0-r11

  • wolfik3d-tools

    < 5.6.0-r11

  • debiangolang-yaml.v2

    < 2.2.8-1 | < 2.2.8-1 | < 2.2.8-1 | < 2.2.8-1

  • gopkg.inyaml.v2

    < 2.2.4

  • gopkg.in/yaml.v2gopkg.in/yaml.v2

    < 2.2.4

  • redhatetcd

    < 0:3.4.14-3.el9ost

  • redhatetcd-debuginfo

    < 0:3.4.14-3.el9ost

  • redhatetcd-debugsource

    < 0:3.4.14-3.el9ost

  • redhatrhc

    < 1:0.2.5-1.el9_5 | < 1:0.2.5-1.el8_10

  • redhatrhc-debuginfo

    < 1:0.2.5-1.el9_5 | < 1:0.2.5-1.el9_5 | < 1:0.2.5-1.el8_10

  • redhatrhc-debugsource

    < 1:0.2.5-1.el9_5 | < 1:0.2.5-1.el9_5 | < 1:0.2.5-1.el8_10

  • redhatrhc-devel

    < 1:0.2.5-1.el9_5

  • redhattoolbox

    < 0:0.0.99.4-1.el9_2

  • redhattoolbox-debuginfo

    < 0:0.0.99.4-1.el9_2

  • redhattoolbox-debugsource

    < 0:0.0.99.4-1.el9_2

  • redhattoolbox-tests

    < 0:0.0.99.4-1.el9_2

  • yaml_projectyaml

    < 2.2.4

References (36)