Crossplane vulnerable to possible image tampering from missing image validation for Packages
CVE-2023-38495

8.4HIGH

Key Information:

Vendor

Crossplane

Vendor
CVE Published:
27 July 2023

What is CVE-2023-38495?

In earlier versions of Crossplane prior to 1.11.5, 1.12.3, and 1.13.0, the image backend failed to verify byte contents of Crossplane packages, potentially allowing an attacker to manipulate package data without detection. To mitigate this risk, users are advised to implement strict controls over package creation and editing privileges, and only utilize images from verified and trusted sources.

Affected Version(s)

crossplane < 1.11.5 < 1.11.5

crossplane >= 1.12.0, < 1.12.3 < 1.12.0, 1.12.3

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.