CVE-2023-27484 is a medium-severity vulnerability in crossplane-runtime, a library used by Crossplane for Kubernetes controllers. Highly privileged users with Composition write access can specify an excessively large index in a patch's ToFieldPath, causing Crossplane to allocate significant memory and potentially leading to a denial of service (OOM-Kill) for the affected Pod. The attack vector is network-based with high privileges required and no user interaction. While the CVSS score is 4.9, the FAUCET Risk Score is 15/100, indicating a relatively low overall risk. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.0, < 1.9.2CPE matchmatch criteria | cpe:2.3:a:crossplane:crossplane:*:*:*:*:*:*:*:* | ||
>= 1.10.0, < 1.10.3CPE matchmatch criteria | cpe:2.3:a:crossplane:crossplane:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.2CPE matchmatch criteria | cpe:2.3:a:crossplane:crossplane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.