One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8317107
Date de publication 2023-03-09 21:15:11 (vue: 2023-03-10 00:06:53)
Titre CVE-2023-27484
Texte crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. In affected versions an already highly privileged user able to create or update Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`, which could lead to excessive memory usage once such Composition is selected for a Composite resource. Compositions allow users to specify patches inserting elements into arrays at an arbitrary index. When a Composition is selected for a Composite Resource, patches are evaluated and if a specified index is greater than the current size of the target slice, Crossplane will grow that slice up to the specified index, which could lead to an excessive amount of memory usage and therefore the Pod being OOM-Killed. The index is already capped to the maximum value for a uint32 (4294967295) when parsed, but that is still an unnecessarily large value. This issue has been addressed in versions 1.11.2, 1.10.3, and 1.9.2. Users are advised to upgrade. Users unable to upgrade can restrict write privileges on Compositions to only admin users as a workaround.
Envoyé Oui
Condensat 2023 27484 4294967295 `tofieldpath` able addressed admin advised affected allow already amount arbitrarily arbitrary are arrays been being build but can capped composite composition compositions controllers could create crossplane current cve elements evaluated excessive greater grow has high highly index inserting issue its killed kubernetes large lead libraries maximum memory once only oom parsed patch patches pod privileged privileges related resource restrict runtime selected set size slice specified specify stacks such target than therefore uint32 unable unnecessarily update upgrade usage used user users value versions when which will workaround write
Tags Guideline
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: