Impact
A flaw in postgres-exporter causes the net/http/pprof package to be imported, adding unprotected debug endpoints to the metrics listener. The exposed pprof endpoints allow an attacker inside the cluster network to obtain sensitive information such as process arguments, goroutine stacks, and database connection strings, and repeated profiling requests can exhaust CPU resources, leading to a denial of service. The weakness is rooted in CWE‑489, exposing internal application details that should be protected.
Affected Systems
Red Hat Multicluster Global Hub is the identified product affected by this issue. The specific versions impacted were not disclosed in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity. EPSS data is not available, but the attack requires only intra‑cluster network access, making exploitation likely for anyone who can reach the metrics port 9187. The issue is not listed in the CISA KEV catalog, so no known widespread exploitation has been reported yet. Given the potential for both information disclosure and service disruption, the risk remains significant for any cluster that permits unrestricted metric port traffic.
OpenCVE Enrichment