kubernetes-metrics: Detect Kubernetes Exposed Metrics

日期: 2025-09-01 | 影响软件: kubernetes-metrics | POC: 已公开

漏洞描述

Information Disclosure of Garbage Collection

PoC代码[已公开]

id: kubernetes-metrics

info:
  name: Detect Kubernetes Exposed Metrics
  author: pussycat0x
  severity: low
  verified: false
  description: Information Disclosure of Garbage Collection
  reference:
    - https://kubernetes.io/docs/concepts/cluster-administration/system-metrics/#metrics-in-kubernetes

rules:
    r0:
        request:
            method: GET
            path: /metrics
        expression: response.status == 200 && response.body.bcontains(b"namespace") && response.body.bcontains(b"HELP") && response.body.bcontains(b"TYPE") && response.body.bcontains(b"kube")
expression: r0() 

相关漏洞推荐