Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf63-g57m-mc5r

Опубликовано: 30 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

EPSS

Процентиль: 33%
0.00395
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-306

Связанные уязвимости

CVSS3: 7.3
ubuntu
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
redhat
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
nvd
19 дней назад

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS3: 7.3
debian
19 дней назад

An unauthenticated remote attacker can bypass access controls by sendi ...

suse-cvrf
12 дней назад

Security update for pcp

EPSS

Процентиль: 33%
0.00395
Низкий

7.3 High

CVSS3

Дефекты

CWE-284
CWE-306