{
  "threat_severity" : "Moderate",
  "public_date" : "2025-12-14T21:27:34Z",
  "bugzilla" : {
    "description" : "kube-controller-manager: Portworx Half-Blind SSRF in kube-controller-manager",
    "id" : "2422109",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2422109"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-918",
  "details" : [ "A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).", "A half-blind Server-Side Request Forgery (SSRF) found in kube-controller-manager that can be triggered when using the legacy in-tree Portworx StorageClass. An authorized user with sufficient privileges can cause the controller to make requests to internal, host-network–accessible endpoints, potentially leaking sensitive information from unprotected services." ],
  "statement" : "This issue is classified as a Moderate vulnerability rather than an Important flaw because its exploitability and impact are significantly constrained by design and configuration prerequisites. Exploitation requires pre-existing high privileges, as the attacker must already be authorized to create pods using the legacy in-tree Portworx StorageClass, which is typically restricted in production clusters. The SSRF is half-blind, limiting the attacker’s ability to reliably control requests or exfiltrate data, and it only becomes meaningful when unprotected endpoints are exposed on the control plane host network, a condition that does not exist in properly hardened environments. There is no direct integrity or availability impact, no privilege escalation, and no code execution path. Additionally, the affected component is disabled by default in supported Kubernetes versions, further reducing real-world exposure. These technical constraints and dependency on non-default or misconfigured setups justify a moderate severity assessment rather than classification as an important flaw.",
  "package_state" : [ {
    "product_name" : "Builds for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-builds/openshift-builds-shared-resource-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_builds:1"
  }, {
    "product_name" : "Builds for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-builds/openshift-builds-shared-resource-webhook-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_builds:1"
  }, {
    "product_name" : "cert-manager Operator for Red Hat OpenShift",
    "fix_state" : "Affected",
    "package_name" : "cert-manager/cert-manager-operator-rhel9",
    "cpe" : "cpe:/a:redhat:cert_manager:1"
  }, {
    "product_name" : "External Secrets Operator for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/bitwarden-sdk-server-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:1"
  }, {
    "product_name" : "External Secrets Operator for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-operator-bundle",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:1"
  }, {
    "product_name" : "External Secrets Operator for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-operator-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:1"
  }, {
    "product_name" : "External Secrets Operator for Red Hat OpenShift",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:1"
  }, {
    "product_name" : "external secrets operator for Red Hat OpenShift - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/bitwarden-sdk-server-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:0"
  }, {
    "product_name" : "external secrets operator for Red Hat OpenShift - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-operator-bundle",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:0"
  }, {
    "product_name" : "external secrets operator for Red Hat OpenShift - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-operator-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:0"
  }, {
    "product_name" : "external secrets operator for Red Hat OpenShift - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "external-secrets-operator/external-secrets-rhel9",
    "cpe" : "cpe:/a:redhat:external_secrets_operator:0"
  }, {
    "product_name" : "Logical Volume Manager Storage",
    "fix_state" : "Fix deferred",
    "package_name" : "lvms4/lvms-must-gather-rhel9",
    "cpe" : "cpe:/a:redhat:lvms:4"
  }, {
    "product_name" : "Logical Volume Manager Storage",
    "fix_state" : "Fix deferred",
    "package_name" : "lvms4/lvms-operator-bundle",
    "cpe" : "cpe:/a:redhat:lvms:4"
  }, {
    "product_name" : "Logical Volume Manager Storage",
    "fix_state" : "Fix deferred",
    "package_name" : "lvms4/lvms-rhel9-operator",
    "cpe" : "cpe:/a:redhat:lvms:4"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/cluster-curator-controller-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Fix deferred",
    "package_name" : "flightctl",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "flightctl",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "flightctl",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alert-exporter-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alertmanager-proxy-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-api-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-cli-artifacts-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-db-setup-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-periodic-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-telemetry-gateway-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-ui-ocp-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-ui-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-userinfo-proxy-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat Edge Manager preview",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-worker-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "microshift",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/cnf-tests-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/cnf-tests-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/kubevirt-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/metallb-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/microshift-bootc-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/noderesourcetopology-scheduler-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/numaresources-must-gather-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/numaresources-operator-bundle",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/numaresources-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-aws-cloud-controller-manager-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-aws-ebs-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-aws-efs-csi-driver-container-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-azure-disk-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-azure-file-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-azure-workload-identity-webhook-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-autoscaler-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-capacity-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-kube-controller-manager-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-kube-controller-manager-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-node-tuning-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-policy-controller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-driver-manila-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-driver-nfs-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-driver-shared-resource-mustgather-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-driver-shared-resource-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-driver-shared-resource-webhook-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-csi-external-provisioner-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-docker-builder-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-gcp-cloud-controller-manager-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-gcp-cloud-controller-manager-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-gcp-filestore-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-hyperkube",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-hyperkube-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-ibm-vpc-block-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-kube-proxy",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-kube-proxy-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-local-storage-diskmaker-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-local-storage-mustgather-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-local-storage-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-multus-admission-controller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-multus-cni-microshift-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-multus-cni-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-multus-networkpolicy-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-node-feature-discovery-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-oauth-apiserver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-olm-catalogd-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-olm-operator-controller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-openshift-apiserver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-openshift-controller-manager-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-openstack-cinder-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-openstack-cloud-controller-manager-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-smb-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-vertical-pod-autoscaler-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-vmware-vsphere-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-vsphere-csi-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-vsphere-csi-driver-syncer-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ztp-site-generate-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "ose-gcp-gcr-image-credential-provider",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Fix deferred",
    "package_name" : "odf4/cephcsi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat OpenShift for Windows Containers",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4-wincw/windows-machine-config-operator-bundle",
    "cpe" : "cpe:/a:redhat:windows_machine_config"
  }, {
    "product_name" : "Red Hat OpenShift for Windows Containers",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4-wincw/windows-machine-config-rhel9-operator",
    "cpe" : "cpe:/a:redhat:windows_machine_config"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-agent-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-extensions-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argo-rollouts-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/console-plugin-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/dex-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/gitops-operator-bundle",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/gitops-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/gitops-rhel8-operator",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/must-gather-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel8/osp-director-agent",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel8/osp-director-downloader",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel8/osp-director-operator",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel8/osp-director-operator-bundle",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel9/osp-director-agent",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel9/osp-director-downloader",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel9/osp-director-operator",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel9/osp-director-operator-bundle",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-13281\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-13281\nhttps://github.com/kubernetes/kubernetes/issues/135525\nhttps://groups.google.com/g/kubernetes-security-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ" ],
  "name" : "CVE-2025-13281",
  "mitigation" : {
    "value" : "No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}