5.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Description
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control planeβs host network (including link-local or loopback services).
Basic Information
ID
CVE-2025-13281
Source
kubernetes
Published
Dec 14, 2025 at 21:27
Modified
Dec 14, 2025 at 22:05
Affected Product
Vendor
Kubernetes
Product
Kubernetes
Version
v1.30.0
Affected Versions
Kubernetes Kubernetes v1.30.0
Kubernetes Kubernetes v1.31.0
Kubernetes Kubernetes v1.32.0
Kubernetes Kubernetes v1.33.0
Kubernetes Kubernetes v1.34.0
Kubernetes Kubernetes v1.31.0
Kubernetes Kubernetes v1.32.0
Kubernetes Kubernetes v1.33.0
Kubernetes Kubernetes v1.34.0