Lucene search

K
hackeroneIamthefrogyH1:1102283
HistoryFeb 12, 2021 - 5:37 p.m.

Engel & Völkers Technology GmbH: CVE-2019-11248 on alertmanager.ev-cloud-platform.engelvoelkers.com

2021-02-1217:37:56
iamthefrogy
hackerone.com
410

0.601 Medium

EPSS

Percentile

97.8%

Summary:

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

Steps To Reproduce:

Navigate to the following URL.
https://alertmanager.ev-cloud-platform.engelvoelkers.com/debug/pprof/

Supporting Material/References:

https://nvd.nist.gov/vuln/detail/CVE-2019-11248
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11248

Attachments

Information disclosure screenshots attached

Impact

The go pprof endpoint is exposed over the Kubelet’s healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service.