Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3019

Опубликовано: 27 мар. 2024
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.

Отчет

As this flaw allows a attacker from the local network to execute arbitrary code and it requires the pmproxy service to be running, which is not the default, it has been rated with an important severity. PCP, as shipped in Red Hat Enterprise Linux 6 and 7, is not affected by this vulnerability because the Redis server backend is not enabled and exposed via pmproxy. Additionally, RHEL9 is not exploitable if the redis:7 module is installed instead of the default Redis version 6.

Меры по смягчению последствий

To mitigate this flaw, stop and disable the pmproxy.service or disable the Redis server backend via the pmproxy configuration file. To stop and disable the pmproxy.service, run the following command:

# systemctl disable --now pmproxy.service

To disable the Redis backend server via the pmproxy configuration file:

# sed -i 's/redis.enabled = true/redis.enabled = false/g' /etc/pcp/pmproxy/pmproxy.conf # systemctl restart pmproxy.service

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pcpNot affected
Red Hat Enterprise Linux 7pcpNot affected
Red Hat Enterprise Linux 8pcpFixedRHSA-2024:326422.05.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportpcpFixedRHSA-2024:339228.05.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportpcpFixedRHSA-2024:332323.05.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicepcpFixedRHSA-2024:332323.05.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionspcpFixedRHSA-2024:332323.05.2024
Red Hat Enterprise Linux 8.6 Extended Update SupportpcpFixedRHSA-2024:332423.05.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportpcpFixedRHSA-2024:332223.05.2024
Red Hat Enterprise Linux 9pcpFixedRHSA-2024:256630.04.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-668
https://bugzilla.redhat.com/show_bug.cgi?id=2271898pcp: exposure of the redis server backend allows remote command execution via pmproxy

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.

CVSS3: 8.8
nvd
около 1 года назад

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.

CVSS3: 8.8
debian
около 1 года назад

A flaw was found in PCP. The default pmproxy configuration exposes the ...

rocky
около 1 года назад

Important: pcp security update

rocky
около 1 года назад

Important: pcp security, bug fix, and enhancement update

8.8 High

CVSS3