GHSA-vfvj-3m3g-m532
MODERATECVE-2023-27483Fuzz testing on crossplane/crossplane, by Ada Logics and sponsored by the CNCF, identified input to a function in the fieldpath package that can cause an out of memory panic. Applications that use the Paved type's SetValue method with user provided input without proper validation might use excessive amounts of memory and cause an out of memory panic.
- Affected
- >= 0.17.0, < 0.19.2, >= 0.6.0, < 0.16.1
- Fixed in
- 0.19.2
- Weakness
- CWE-20
- Published
- 2023-03-13
- Source
- github