Deserialization of Untrusted Data in yaml - CVE-2022-28948

 

Deserialization of Untrusted Data in yaml - CVE-2022-28948

Published: June 14, 2022


Vulnerability identifier: #VU64275
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28948
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insecure input validation when processing serialized data in the Unmarshal function. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

yaml
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
HPC Module
openSUSE Leap
Service Binding Operator
Cryostat
IBM MQ Operator
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Argo CD
IBM Cloud Pak for Watson AIOps
Storage Defender – Data Protect
ObjectScale
Watson CP4D Data Stores
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
IBM API Connect
ignition-debuginfo
ignition-dracut-grub2
ignition

How to mitigate CVE-2022-28948

Install updates from vendor's website.

yaml - update to 3.0.1
Service Binding Operator - addressed in versions 1.3.4, 1.4.0
Cryostat - update to 2.1.1
Argo CD - addressed in versions 2.2.12, 2.3.7, 2.4.8
IBM API Connect - update to 10.0.8.5
Storage Defender – Data Protect - update to 1.4.0
ObjectScale - update to 1.4.0
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
ignition-debuginfo - addressed in versions 2.14.0-150300.4.16.1, 2.14.0-150300.6.16.1, 2.14.0-150400.4.12.1, 2.14.0-150400.9.12.1
ignition-dracut-grub2 - addressed in versions 2.14.0-150300.4.16.1, 2.14.0-150300.6.16.1, 2.14.0-150400.4.12.1, 2.14.0-150400.9.12.1
ignition - addressed in versions 2.14.0-150300.4.16.1, 2.14.0-150300.6.16.1, 2.14.0-150400.4.12.1, 2.14.0-150400.9.12.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
Watson CP4D Data Stores - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10

External References

Related Security Bulletins