S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-11248 Scanner

Detects 'Information Disclosure' vulnerability in Kubernetes affects v. prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10.

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
44
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-11248
8.2
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Kubernetesby Kubernetes
prior to 1.12.10
Updated Aug 21, 2026View on NVD →
Detail

Kubernetes is an open-source container orchestration platform that automates the deployment, scaling, and management of containerized applications. It is widely used to manage complex distributed systems and microservices-based applications in enterprise environments. The platform provides a uniform way to deploy, manage, and scale applications across various environments, such as on-premises or public clouds. Kubernetes has become an industry standard for container orchestration, empowering businesses to run complex workloads at scale with ease.

The CVE-2019-11248 vulnerability is a security flaw in Kubernetes versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10. The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port, potentially leaking sensitive information about the internal Kubelet memory addresses and configuration. This can lead to a limited denial of service attack or other security issues.

When exploited, this vulnerability can enable attackers to gain access to sensitive information, such as memory addresses and configurations, compromising the security of the entire Kubernetes system. The potential access to sensitive data, in turn, can lead to data breaches or other security incidents that might result in significant financial losses or damage to reputation for enterprises utilizing Kubernetes.

Thanks to the pro features of the s4e.io platform, Kubernetes users can easily and quickly learn about vulnerabilities in their digital assets. As a leading cybersecurity solution, S4E leverages advanced machine learning capabilities to facilitate end-to-end security for Kubernetes deployments. Our platform helps enterprises identify potential vulnerabilities and assists with remediation to prevent information disclosure and other security threats.

 

REFERENCES

Solution Advice

To protect against the CVE-2019-11248 vulnerability and other potential threats, enterprises can consider the following precautions:

  • Ensure that the Kubernetes version is 1.15.0, 1.14.4, 1.13.8, or 1.12.10 to avoid exposure to this vulnerability
  • Limit the exposure of the Kubelet healthz port on production environments to mitigate the possibility of information disclosure 
  • Implement network security solutions such as firewalls to control access to the Kubernetes infrastructure
  • Implement a security-layer overlay to the Kubernetes API to maintain end-to-end secure connectivity between users and the Kubernetes API endpoint
  • Implement secure communication between Kubernetes nodes and the control plane

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-11248 scanner - Information Disclosure vulnerability in Kubernetes | S4E