Crossplane vulnerable to possible image tampering from missing image validation for Packages
CVE-2023-38495
8.4HIGH
What is CVE-2023-38495?
In earlier versions of Crossplane prior to 1.11.5, 1.12.3, and 1.13.0, the image backend failed to verify byte contents of Crossplane packages, potentially allowing an attacker to manipulate package data without detection. To mitigate this risk, users are advised to implement strict controls over package creation and editing privileges, and only utilize images from verified and trusted sources.
Affected Version(s)
crossplane < 1.11.5 < 1.11.5
crossplane >= 1.12.0, < 1.12.3 < 1.12.0, 1.12.3
