Multiple Information Disclosure with Go PPROF on api-ne.mackeeper.com
Team Summary
Official summary from Clario
## Summary Multiple Information Disclosure with Go PPROF on `api-ne.mackeeper.com`. ## Steps To Reproduce Go to: `https://api-ne.mackeeper.com/debug/pprof/` You will see these links: - allocs: A sampling of all past memory allocations - block: Stack traces that led to blocking on synchronization primitives - cmdline: The command line invocation of the current program - goroutine: Stack traces of all current goroutines - heap: A sampling of memory allocations of live objects. You can specify the gc GET parameter to run GC before taking the heap sample. - mutex: Stack traces of holders of contended mutexes - profile: CPU profile. You can specify the duration in the seconds GET parameter. After you get the profile file, use the go tool pprof command to investigate the profile. - threadcreate: Stack traces that led to the creation of new OS threads - trace: A trace of execution of the current program. You can specify the duration in the seconds GET parameter. After you get the trace file, use the go tool trace command to investigate the trace.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure