PT-2026-104649 · Crossplane · Crossplane-Runtime
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
crossplane crossplane-runtime versions 2.2.0 through 2.2.2
crossplane crossplane-runtime versions 2.3.0 through 2.3.2
Description
A time-of-check time-of-use (TOCTOU) issue exists in the
ImageConfig component within the Get() function of the pkg/xpkg/client.go file. This occurs when package signature verification is enabled and packages are installed using tag references instead of digests from registries not controlled by the user. A malicious OCI registry could provide a correctly signed image during the verification step and subsequently serve an unsigned or malicious image during the installation step because the tag reference is resolved separately for each action. This allows for the remote installation of unverified package content.Recommendations
Update crossplane crossplane-runtime versions 2.2.0 through 2.2.2 to version 2.2.3.
Update crossplane crossplane-runtime versions 2.3.0 through 2.3.2 to version 2.3.3.
Install packages by image digest rather than using tags to avoid this issue.
Exploit
Fix
Time Of Check To Time Of Use
Race Condition
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crossplane-Runtime