Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-07-27T18:07:13.283Z

Updated: 2024-08-02T17:46:55.228Z

Reserved: 2023-07-18T16:28:12.076Z

Link: CVE-2023-38495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-07-27T19:15:10.010

Modified: 2023-08-03T13:39:31.713

Link: CVE-2023-38495

cve-icon Redhat

No data.