Back

HIGH

Kubernetes kubelet exposes /debug/pprof info on healthz port

Published Aug 29, 2019

Description

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

Affected products

Remediation

Vendor solution

update node configurations to set the "healthzBindAddress" to "127.0.0.1" to prevent access by remote callers.

Red Hat statement

OpenShift Container Platform 3 is not vulnerable to this flaw as the kubelet healthz server is disabled by default. OpenShift Container Platform 4 enables the /debug/pprof endpoint on the kubelet healthz server to local traffic only. There are multiple reasons why this has been rated as moderate by Red Hat. 1. Firstly, even though the endpoint is vulnerable, not all Kubernetes deployments expose the healthz /debug/pprof interface to untrusted networks. Many use network policies or restrict that port to internal or localhost. SUSE’s advisory explicitly notes that the debugging endpoint “is not exposed by the default configuration.” 2. While the biggest impact is confidentiality, theoretical leakage of internal state or memory, there is no integrity or full service takeover.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Aug 29, 2019
Updated Sep 17, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 7, 2019