openwall.com
http://www.openwall.com/lists/oss-security/2025/12/01/4 CVE-2025-13281
MEDIUM
Portworx Half-Blind SSRF in kube-controller-manager
Record summary
CVE-2025-13281 has a selected CVSS score of 5.8 (medium).
Description
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 15, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubernetesBrowse Kubernetes / KubernetesDefault status: unaffected | CVE List | v1.30.0 to ≤ v1.30.14 | affected |
| v1.31.0 to ≤ v1.31.14 | affected | ||
| v1.32.0 to ≤ v1.32.9 | affected | ||
| v1.33.0 to ≤ v1.33.5 | affected | ||
| v1.34.0 to ≤ v1.34.1 | affected | ||
k8s.io/kubernetesBrowse Go / k8s.io/kubernetes | GitHub Advisory | Before 1.32.10 · Fixed in 1.32.10 | affected |
| 1.33.0-alpha.0 to < 1.33.6 · Fixed in 1.33.6 | affected | ||
| 1.34.0-alpha.0 to < 1.34.2 · Fixed in 1.34.2 | affected |
References
9github.com
https://github.com/advisories/GHSA-r6j8-c6r2-37rr github.com
https://github.com/kubernetes/kubernetes github.com
https://github.com/kubernetes/kubernetes/commit/7506ce804c20696ba32cdb72126270ceaed06e24 github.com
https://github.com/kubernetes/kubernetes/commit/97650c1c4fe15cbb7756ba95b3edc8a8665063ca github.com
https://github.com/kubernetes/kubernetes/commit/dbe17dfe7773563eac95534040f413ada6d2b421 github.comissue tracking
https://github.com/kubernetes/kubernetes/issues/135525 groups.google.commailing list
https://groups.google.com/g/kubernetes-security-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13281