VDB
Sign up
MEDIUM5.8

GHSA-r6j8-c6r2-37rr

kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass

Quick fix

GHSA-r6j8-c6r2-37rr — k8s.io/kubernetes: upgrade to the fixed version with the command below.

go get k8s.io/kubernetes@v1.32.10

Details

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/kubernetes
Introduced in: 0Fixed in: 1.32.10
Fixgo get k8s.io/kubernetes@v1.32.10
Go/k8s.io/kubernetes
Introduced in: 1.33.0-alpha.0Fixed in: 1.33.6
Fixgo get k8s.io/kubernetes@v1.33.6
Go/k8s.io/kubernetes
Introduced in: 1.34.0-alpha.0Fixed in: 1.34.2
Fixgo get k8s.io/kubernetes@v1.34.2

References