CVE
GHSA-mf7q-r4rv-jv94
Crossplane-runtime versions 2.3.0 through 2.3.2 contain a time-of-check time-of-use vulnerability in package signature verification. The flaw exists because the package manager resolves tag references independently during signature verification and image fetching operations, rather than using a single resolved digest for both steps. When a user configures image signature verification through the ImageConfig mechanism and installs a package using a tag reference from an untrusted OCI registry, a malicious registry operator can serve a correctly signed image during the verification phase and subsequently serve a different unsigned image during the installation phase. This occurs because the tag-to-digest resolution is performed twice, allowing the registry to return different manifests for each request. The impact is a compromise of integrity guarantees, permitting the installation of unverified or malicious package content despite signature verification being enabled. The affected funct...
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
-

C
H
U
-

C
H
U
9
-
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Related Resources
No items found.