logo

Database

Server-side request forgery (SSRF) In k8s.io/kubernetes

Description

kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions