Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.
History

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Crossplane
Crossplane crossplane
CPEs cpe:2.3:a:crossplane:crossplane:*:*:*:*:*:*:*:*
Vendors & Products Crossplane
Crossplane crossplane
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-07-27T18:07:13.283Z

Updated: 2024-10-10T18:00:40.652Z

Reserved: 2023-07-18T16:28:12.076Z

Link: CVE-2023-38495

cve-icon Vulnrichment

Updated: 2024-08-02T17:46:55.228Z

cve-icon NVD

Status : Modified

Published: 2023-07-27T19:15:10.010

Modified: 2024-11-21T08:13:41.513

Link: CVE-2023-38495

cve-icon Redhat

No data.