Server-side request forgery (SSRF) In k8s.io/kubernetes
Description
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1.20.5+really1.20.2-1 | ||
debian 13 | 1.20.5+really1.20.2-1 | ||
go | 1.32.10, 1.33.6, 1.34.2 | ||
debian 11 | 1.20.5+really1.20.2-1 | ||
debian 12 | 1.20.5+really1.20.2-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6.