CVE 5.8 MEDIUM

Portworx Half-Blind SSRF in kube-controller-manager_CVE-2025-13281

5.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Basic Information

ID CVE-2025-13281
Source kubernetes
Published Dec 14, 2025 at 21:27
Modified Dec 14, 2025 at 22:05

Affected Product

Vendor Kubernetes
Product Kubernetes
Version v1.30.0
Affected Versions Kubernetes Kubernetes v1.30.0
Kubernetes Kubernetes v1.31.0
Kubernetes Kubernetes v1.32.0
Kubernetes Kubernetes v1.33.0
Kubernetes Kubernetes v1.34.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.