Record summary

CVE-2025-13281 has a selected CVSS score of 5.8 (medium).

Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 15, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE Listv1.30.0 to ≤ v1.30.14affected
v1.31.0 to ≤ v1.31.14affected
v1.32.0 to ≤ v1.32.9affected
v1.33.0 to ≤ v1.33.5affected
v1.34.0 to ≤ v1.34.1affected
GitHub AdvisoryBefore 1.32.10 · Fixed in 1.32.10affected
1.33.0-alpha.0 to < 1.33.6 · Fixed in 1.33.6affected
1.34.0-alpha.0 to < 1.34.2 · Fixed in 1.34.2affected

References

9