K8s Security: [Security Advisory] CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager
Open
external
kubernetes
on-call
security
- Dominant language
- Shell
- Stars
- 1.5k
- Forks
- 198
- Avg merge
- 10h 46m
- Merged PRs (30d)
- 28
Description
Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.
Follow the on-call runbook to backport fixes to all supported versions.
Contributor guide
Research direction
Start with the Kubernetes security announcement linked in the issue, then follow the on-call runbook for the backport process. Identify all supported versions covered by the runbook and verify that the CVE fix has been backported to each one; done means the supported-version updates are complete.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100