CVE-2019-11248
Summary
| CVE | CVE-2019-11248 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-29 01:15:00 UTC |
| Updated | 2020-10-05 13:50:00 UTC |
| Description | The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | rc1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | rc2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.1 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.1 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.2 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.2 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.3 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.3 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.4 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.4 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.5 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.5 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.6 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.6 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.7 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.7 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.8 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | rc1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.1 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.1 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.2 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.2 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.3 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.3 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.4 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | rc1 | All | All |
| Application | Kubernetes | Kubernetes | All | All | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | rc1 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.0 | rc2 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.1 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.1 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.2 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.2 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.3 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.3 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.4 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.4 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.5 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.5 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.6 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.6 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.7 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.13.7 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.13.8 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.0 | rc1 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.1 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.1 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.2 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.2 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.3 | - | All | All |
| Application | Kubernetes | Kubernetes | 1.14.3 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.14.4 | beta.0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha1 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha2 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | alpha3 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta0 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta1 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | beta2 | All | All |
| Application | Kubernetes | Kubernetes | 1.15.0 | rc1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-11248: /debug/pprof exposed on kubelet's healthz port · Issue #81023 · kubernetes/kubernetes · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Google Groups | MLIST | groups.google.com | Mailing List, Third Party Advisory |
| September 2019 Kubernetes Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Jordan Zebor, F5 Networks
Legacy QID Mappings
- 730928 Kubernetes Kubelet Missing Authorization Vulnerability