Portworx Half-Blind SSRF in kube-controller-manager
Vulnerability Description
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13281
Credits & Attribution
No credits recorded in the NVD database.
References
More from Kubernetes
View All →Affected Vendor
Kubernetes
View all reports →