CVE-2023-37900Low· 3.4▾ SunlitDenial of service from large image
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
An high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse, possibly resulting in exhausting all the available memory and therefore in the container being OOMKilled.
The impact is low due to the high privileges required to be able to create the Package and the eventually consistency nature of controller.
The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0, all the supported versions of Crossplane at the time of writing.
Only using images from trusted sources and keeping Package editing/creating privileges to administrators only, which should be both considered already best practices.
See ADA-XP-23-16 in the Security Audit's report.
This was reported as ADA-XP-23-16 by @AdamKorcz and @DavidKorczynski from Ada Logic and facilitated by OSTIF as part of the Security Audit sponsored by CNCF.
github.com/crossplane/crossplane < 1.11.5github.com/crossplane/crossplane >= 1.12.0, < 1.12.3Upgrade to a patched release:
github.com/crossplane/crossplane 1.11.5github.com/crossplane/crossplane 1.12.3Connected by shared product, vendor, weakness, or advisory.
GHSA-7h65-4p22-39j6Critical· 9.8github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
GO-2024-3219Nonegithub.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
GO-2026-6302NoneSignature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
GHSA-mf7q-r4rv-jv94HighCrossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…
GHSA-wfqx-gjrf-g28rCritical· 9.0Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag