CVE-2019-11248: Debug Endpoint pprof – Exposure Detection

CVE-2019-11248: Debug Endpoint pprof - Exposure Detection-渗透云记 - 专注于网络安全与技术分享
CVE-2019-11248: Debug Endpoint pprof – Exposure Detection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-11248: Debug Endpoint pprof – Exposure Detection

漏洞描述

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享