CVE-2025-13281

EUVD-2025-203310
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
kubernetesCNA
5.8 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
kuberneteskubernetes
1.30.0 ≤
𝑥
≤ 1.30.14
CNA
kuberneteskubernetes
1.31.0 ≤
𝑥
≤ 1.31.14
CNA
kuberneteskubernetes
1.32.0 ≤
𝑥
≤ 1.32.9
CNA
kuberneteskubernetes
1.33.0 ≤
𝑥
≤ 1.33.5
CNA
kuberneteskubernetes
1.34.0 ≤
𝑥
≤ 1.34.1
CNA