CVE-2023-38495
As such, Crossplane does not detect if an attacker has tampered with a Package.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cncf/crossplane
- Source
- security-advisories@github.com
References
- https://github.com/crossplane/crossplane/blob/ac8b24fe739c5d942ea885157148497f196c3dd3/security/ADA-security-audit-23.pdfExploit, Technical Description, Vendor Advisory
- https://github.com/crossplane/crossplane/security/advisories/GHSA-pj4x-2xr5-w87mVendor Advisory
- https://github.com/crossplane/crossplane/blob/ac8b24fe739c5d942ea885157148497f196c3dd3/security/ADA-security-audit-23.pdfExploit, Technical Description, Vendor Advisory
- https://github.com/crossplane/crossplane/security/advisories/GHSA-pj4x-2xr5-w87mVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.