Knowledge BaseSolutionsRemediate Redis, etcd, and pprof vulnerabilities in ZStack Cloud

Remediate Redis, etcd, and pprof vulnerabilities in ZStack Cloud

SolutionsZCF · CloudVersions4.8.x / 4.6.xArticle IDKB-200099Updated2026-09-16

Applicable scenario

  • Product: ZCF
  • Component: Cloud
  • Versions: 4.8.x, 4.6.x
  • Deployment topology: dual management nodes
  • Trigger: A vulnerability scan finds exposed go-pprof and etcd ports and unauthorized Redis access.

Symptoms

  • The environment has:
  • poc-yaml-go-pprof-leak
  • poc-yaml-etcd-unauth
  • Unauthorized Redis access
  • Remediation focuses on:
  • 9091
  • 2379
  • Redis authentication configuration

Sign in to view the rest of this article, plus more troubleshooting and solution know-how.

Remediate Redis, etcd, and pprof vulnerabilities in ZStack Cloud | KB-200099 | ZStack Resource Center