SCA: security update for github.com/crossplane/crossplane (GHSA-v829-x6hh-cqfq)

medium Tenable Self-Hosted Container Security Plugin ID 419175

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its
related stacks. In affected versions an already highly privileged user able to create or update
Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`, which could lead to
excessive memory usage once such Composition is selected for a Composite resource. Compositions allow
users to specify patches inserting elements into arrays at an arbitrary index. When a Composition is
selected for a Composite Resource, patches are evaluated and if a specified index is greater than the
current size of the target slice, Crossplane will grow that slice up to the specified index, which could
lead to an excessive amount of memory usage and therefore the Pod being OOM-Killed. The index is already
capped to the maximum value for a uint32 (4294967295) when parsed, but that is still an unnecessarily
large value. This issue has been addressed in versions 1.11.2, 1.10.3, and 1.9.2. Users are advised to
upgrade. Users unable to upgrade can restrict write privileges on Compositions to only admin users as a
workaround. (CVE-2023-27484)

See Also

https://github.com/advisories/GHSA-v829-x6hh-cqfq

Plugin Details

Severity: Medium

ID: 419175

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:N/A:C

CVSS Score Source: CVE-2023-27484

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/10/2023

Vulnerability Publication Date: 3/9/2023

Reference Information

CVE: CVE-2023-27484