Database/Container, Kubernetes & orchestration
Kubernetes (kube-controller-manager): Half-blind SSRF via the Portworx in-tree volume plugin in kube-controller-manager
CVSS 5.8CVE-2025-13281Container, Kubernetes & orchestrationcurated
Impact
Half-blind SSRF via the Portworx in-tree volume plugin in kube-controller-manager
Who can reach it
Cluster user able to create a Portworx volume
What to do
Rolling control-plane upgrade; remove the in-tree Portworx plugin
References
Related entries
- Kubernetes (kube-controller-manager): Ceph RBD admin secrets written to controller-manager logsCVE-2020-8566 · Kubernetes (kube-controller-manager)Medium
- Kubernetes (kube-controller-manager): Half-blind SSRF from the controller manager into the cloud metadata serviceCVE-2020-8555 · Kubernetes (kube-controller-manager)Medium
- Kata Containers: Default configuration allows pod creators more than intendedCVE-2026-44210 · Kata ContainersMedium
- Kuma: Universal-mode dataplane skips TLS verification, exposing its token to proxy takeoverCVE-2026-52724 · Kuma kuma-dp (Universal mode control-plane TLS verification)Medium
- KubePi: authenticated cluster manager can read and modify clusters outside their granted scopeCVE-2026-69129 · KubePi (cluster-scoped API authorization)Medium
- containerd: Goroutine leak in the CRI stream server terminal-resize path exhausts host memoryCVE-2022-23471 · containerdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.