Impact
The vulnerability is a time‑of‑check/time‑of‑use race condition in the ImageConfig Get function of crossplane‑runtime. An attacker can manipulate the state between the check and the use of an image configuration, potentially allowing unauthorized manipulation of deployment details or execution of code with the privileges of the service. This flaw is classified under CWE‑362 and CWE‑367. The flaw can be exploited over the network, giving an attacker a remote entry point into the system.
Affected Systems
The issue affects crossplane crossplane‑runtime versions up to 2.2.2 and 2.3.2. Updating to 2.2.3, 2.3.3 or the 2.4.0‑rc.1 release removes the bug.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity, and the EPSS score is unavailable, suggesting no current public exploitation data. It is not listed in the CISA KEV catalog. Because the failure is a race condition that can be triggered remotely, the risk is that a remote attacker can manipulate image configuration handling, leading to potential privilege escalation or code execution. The lack of known exploitation does not reduce the importance of patching, as the underlying race condition remains exploitable by a determined adversary.
OpenCVE Enrichment