fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime
CVE-2023-27483

5.9MEDIUM

Key Information:

Vendor

Crossplane

Vendor
CVE Published:
9 March 2023

What is CVE-2023-27483?

A vulnerability has been identified in the Crossplane runtime libraries related to the Paved type's SetValue method, which could lead to an out of memory panic. When user-provided input is not properly validated, the method may permit excessive memory allocation. Specifically, this issue arises when values are set in slices using indices provided in the input, which are directly parsed without validation. The index is allowed to grow to a maximum value of uint32 (4294967295), creating a risk for memory exhaustion. Applications relying on the SetValue method should validate and constrain input sizes to prevent potential memory consumption vulnerabilities. This issue has been rectified in versions 0.16.1 and 0.19.2, and users are strongly encouraged to upgrade or implement input validation.

Affected Version(s)

crossplane-runtime >= 0.17.0, < 0.19.2 < 0.17.0, 0.19.2

crossplane-runtime < 0.16.1 < 0.16.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.