Skip to content

Vulnerability found in gopkg.in/yaml.v2 in versions < 2.2.8 (CVE-2019-11254) #9

@hiltol

Description

@hiltol

Our scans (using Mend) detected CVE-2019-11254 in the go-yaml package for versions <2.2.8. More details here
GHSA-wxc4-f4m6-wwqv

The recommended fix is to upgrade to at least https://github.com/go-yaml/yaml/tree/v2.2.8

From my understanding, the code in this module is based on an earlier version of go-yaml. Can the go-yaml code base be upgraded to address this vulnerability?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions