漏洞描述 Kubernetes(简称K8SQ)是Google在2014年开源的一个容器集群管理系统。它用于容器化应用程序的部署、扩展和管理,目标是让部署容器化应用简单且高效。漏洞存在于Kubernetes的1.18.6版本之前,可能导致未经授权的用户访问攻击。漏洞的细节在于Kubelet组件中存在一个调试端点(/debug/pprof)的暴露,该端点可以通过未经授权的Kubelethealthzi端口访问。
相关漏洞推荐 POC gcloudignore-file-exposure: Google Cloud Ignore File Exposure POC google-calendar-exposure: Google Calendar - Exposure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure POC CVE-2019-11253: Kubernetes API Server - YAML Parsing DoS (Billion Laughs) POC CVE-2025-12139: Integrate Google Drive <= 1.5.3 - Information Disclosure POC gcs-bucket-listing: Google Cloud Storage - Public Bucket Listing POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure POC CVE-2025-11307: WP Google Maps < 9.0.48 - Cross-Site Scripting POC wp-easy-google-fonts-log-disclosure: WordPress Easy Google Fonts - Error Log Disclosure WordPress Google for WooCommerce /wp-content/plugins/google-listings-and-ads/vendor/googleads/google-ads-php/scripts/print_php_information.php 信息泄露漏洞(CVE-2024-10486) POC CVE-2015-2755: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting POC CVE-2017-18556: Google Analytics by BestWebSoft < 1.7.1 - Cross-Site Scripting POC CVE-2017-18557: Google Maps by BestWebSoft < 1.3.6 - Cross-Site Scripting