- Description
- A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
- Source
- jordan@liggitt.net
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 5.8
- Impact score
- 4
- Exploitability score
- 1.3
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
- Severity
- MEDIUM
- jordan@liggitt.net
- CWE-918
- Hype score
- Not currently trending
CVE-2025-13281 A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allow… https://t.co/rNdGaSGvf7
@CVEnew
15 Dec 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13281 Kubernetes kube-controller-manager Half-Blind SSRF Vulnerability in Portworx StorageClass https://t.co/vgBxPLCZCQ
@VulmonFeeds
14 Dec 2025
66 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager - https://t.co/RqDZoZLBhx
@K8sContributors
2 Dec 2025
723 Impressions
0 Retweets
3 Likes
3 Bookmarks
0 Replies
0 Quotes