The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.12.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.3-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.4-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.5-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.6-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.7-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.7-beta\\.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.13.8-beta\\.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.1-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.2-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.3-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.4-beta\\.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-alpha0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-alpha1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-alpha2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-alpha3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.1-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.2-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.3-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.4-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.5-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.13.6-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-alpha0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-alpha1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-alpha2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-alpha3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.1-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.2-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.3-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-alpha0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-alpha1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-alpha2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-alpha3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.15.0-rc1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11248.json"