High severity8.3NVD Advisory· Published Jul 27, 2023· Updated Jun 17, 2026
CVE-2023-38495
CVE-2023-38495
Description
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/crossplane/crossplaneGo | < 1.11.5 | 1.11.5 |
github.com/crossplane/crossplaneGo | >= 1.12.0, < 1.12.3 | 1.12.3 |
Affected products
10- ghsa-coords8 versionspkg:golang/github.com/crossplane/crossplanepkg:apk/wolfi/crossplanepkg:apk/chainguard/crossplane-xfnpkg:apk/chainguard/crossplane-crankpkg:apk/wolfi/crossplane-crankpkg:apk/chainguard/crossplanepkg:bitnami/crossplanepkg:apk/wolfi/crossplane-xfn
< 1.11.5+ 7 more
- (no CPE)range: < 1.11.5
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.11.5
- (no CPE)range: < 0
- Range: < 1.11.5
Patches
Vulnerability mechanics
References
4- github.com/crossplane/crossplane/blob/ac8b24fe739c5d942ea885157148497f196c3dd3/security/ADA-security-audit-23.pdfnvdExploitTechnical DescriptionVendor AdvisoryWEB
- github.com/advisories/GHSA-pj4x-2xr5-w87mghsaADVISORY
- github.com/crossplane/crossplane/security/advisories/GHSA-pj4x-2xr5-w87mnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-38495ghsaADVISORY
News mentions
0No linked articles in our index yet.