Skip to content

Some security advice about debug/pprof #519

@wenyurush

Description

@wenyurush

In an internal security check, a medium-risk vulnerability was found in pushgetway, which was confirmed to be http://x.x.x.x:9091/debug/pprof related information.

According to the introduction may indeed generate some risks

https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/
http://mmcloughlin.com/posts/your-pprof-is-showing

Consider setting a switch to disable the relevant functionality when necessary

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions