{"id":"GO-2025-4240","summary":"Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes","details":"Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes","aliases":["CVE-2025-13281","GHSA-r6j8-c6r2-37rr"],"modified":"2026-02-04T03:00:49.298548Z","published":"2025-12-16T19:39:14Z","related":["CGA-qpfv-qmrf-52w5"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4240"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r6j8-c6r2-37rr"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/12/01/4"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/7506ce804c20696ba32cdb72126270ceaed06e24"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/97650c1c4fe15cbb7756ba95b3edc8a8665063ca"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/dbe17dfe7773563eac95534040f413ada6d2b421"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/135525"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ"}],"affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.32.10"},{"introduced":"1.33.0-alpha.0"},{"fixed":"1.33.6"},{"introduced":"1.34.0-alpha.0"},{"fixed":"1.34.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4240.json"}}],"schema_version":"1.7.3"}