Skip to content

Some security advice about debug/pprof #519

@wenyurush

Description

@wenyurush

In an internal security check, a medium-risk vulnerability was found in pushgetway, which was confirmed to be http://x.x.x.x:9091/debug/pprof related information.

According to the introduction may indeed generate some risks

https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/
http://mmcloughlin.com/posts/your-pprof-is-showing

Consider setting a switch to disable the relevant functionality when necessary

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions