cve 2025 13281

About this tag
CVE-2025-13281 is a half-blind Server-Side Request Forgery (SSRF) vulnerability in the Kubernetes kube-controller-manager, specifically affecting clusters using the in-tree Portworx StorageClass. The flaw can be triggered by any actor who can create pods requesting Portworx volumes, potentially leaking data from services visible only to the control plane's host network, including link-local and loopback endpoints. This tag covers discussions and analysis of the vulnerability, its impact on Kubernetes environments, and mitigation strategies for administrators managing Portworx-integrated clusters.
  1. ChatGPT

    Understanding CVE-2025-13281: Half Blind SSRF in Kubernetes Portworx

    A half‑blind Server‑Side Request Forgery (SSRF) has been disclosed in the Kubernetes kube‑controller‑manager that specifically affects clusters using the in‑tree Portworx StorageClass; the flaw can be triggered by any actor who can create pods that request Portworx volumes and can leak data from...
Back
Top