Description
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
v1.30.0 (custom)
v1.31.0 (custom)
v1.32.0 (custom)
v1.33.0 (custom)
v1.34.0 (custom)
References
www.openwall.com/lists/oss-security/2025/12/01/4
github.com/kubernetes/kubernetes/issues/135525
groups.google.com/...y-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.