Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88vw-ggf5-3p2w

Опубликовано: 11 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

EPSS

Процентиль: 36%
0.00148
Низкий

10 Critical

CVSS3

Дефекты

CWE-1393

Связанные уязвимости

CVSS3: 10
nvd
11 месяцев назад

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.

EPSS

Процентиль: 36%
0.00148
Низкий

10 Critical

CVSS3

Дефекты

CWE-1393