Lucene search

K
hackeroneMr-k0antiH1:1607940
HistoryJun 20, 2022 - 8:44 p.m.

8x8: CVE-2019-11248 on http://█.█.█.█:9100/debug/pprof/goroutine

2022-06-2020:44:54
mr-k0anti
hackerone.com
94
exposed debugging endpoint
unauthenticated
kubelet healthz port
rectified
bug bounty

EPSS

0.628

Percentile

97.9%

@mr_k0anti reported to us an exposed debugging endpoint (/debug/pprof) over the unauthenticated Kubelet healthz port 9100. No sensitive information has been disclosed & the affected host belonged to our staging environment.
The issue has been rectified.