Skip to main content

CVE-2019-11248

8.2
HIGHCVSS v3.1 Base Score
91.21%
HIGH RiskEPSS (100th percentile)

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

Published: 8/29/2019
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

CVSS v2 Score

6.4

AV:N/AC:L/Au:N/C:P/I:N/A:P

EPSS Score (Exploitation Probability)

91.21%HIGH Exploitation Risk
100th percentile

This vulnerability has a 91.21% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Related Vulnerabilities