About:/debug/pprof and CVE-2019-11248,HELP #2802
Unanswered
02darlingX
asked this question in
Q&A
Replies: 1 comment
-
|
Sorry,my debug command was:curl -v http://$nodeip:32667/debug/pprof Then,it came back:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Dear Experts,
The
**/debug/pprof**debugging port has been flagged by our company's security team as a security risk-CVE-2019-11248 during their scans.I have tried several approaches including using NetworkPolicy, and parameters like
**--telemetry-host=127.0.0.1**and-**-telemetry-port=8081**, but none seem to be effective.During verification, when I run
curl -v http://<nodeip>:8080/debug/pprof, the request is still redirected and does not return the expected 404 error.Why do the args: - "--telemetry-host=127.0.0.1", - "--telemetry-port=8081", -
--host=0.0.0.0, ---port=8080not work?Are there any other quick and effective methods besides upgrading?
PS: 1、The Kubernetes cluster version is Alibaba Cloud version 1.18,
and the deployed kube-state-metrics version is 1.9.8.
2、This older version deploys without obvious errors in the logs,
whereas newer versions generate error messages after deployment.So my colleague select the v1.9.8.
3、Expose the metrics port 8080 to the external Prometheus outside the cluster via NodePort 32667 for monitoring collection.
Beta Was this translation helpful? Give feedback.
All reactions