CVE-2023-38495 is a critical vulnerability in Crossplane versions prior to 1.11.5, 1.12.3, and 1.13.0, where the image backend fails to validate package byte contents, allowing attackers to tamper with packages. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, though its FAUCET Risk Score is 77/100. Organizations are advised to update to patched versions or implement workarounds such as using trusted image sources and restricting Package editing privileges.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.5CPE matchmatch criteria | cpe:2.3:a:cncf:crossplane:*:*:*:*:*:*:*:* | ||
>= 1.12.0, < 1.12.3CPE matchmatch criteria | cpe:2.3:a:cncf:crossplane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.