fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime
CVE-2023-27483
What is CVE-2023-27483?
A vulnerability has been identified in the Crossplane runtime libraries related to the Paved type's SetValue method, which could lead to an out of memory panic. When user-provided input is not properly validated, the method may permit excessive memory allocation. Specifically, this issue arises when values are set in slices using indices provided in the input, which are directly parsed without validation. The index is allowed to grow to a maximum value of uint32 (4294967295), creating a risk for memory exhaustion. Applications relying on the SetValue method should validate and constrain input sizes to prevent potential memory consumption vulnerabilities. This issue has been rectified in versions 0.16.1 and 0.19.2, and users are strongly encouraged to upgrade or implement input validation.
Affected Version(s)
crossplane-runtime >= 0.17.0, < 0.19.2 < 0.17.0, 0.19.2
crossplane-runtime < 0.16.1 < 0.16.1
