Логотип exploitDog
bind:CVE-2023-38495
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38495

Количество 2

Количество 2

nvd логотип

CVE-2023-38495

больше 2 лет назад

Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-pj4x-2xr5-w87m

больше 2 лет назад

Possible image tampering from missing image validation for Packages

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38495

Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.

CVSS3: 8.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-pj4x-2xr5-w87m

Possible image tampering from missing image validation for Packages

CVSS3: 8.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу