Описание
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Отчет
This is an Important flaw in Performance Co-Pilot (PCP) pmproxy that allows an unauthenticated remote attacker to bypass pmcd access controls. By sending crafted requests to the /store endpoint, an attacker can write to any Performance Metrics Domain Agent (PMDA) metric, potentially leading to arbitrary code execution if pmproxy is running and reachable on its default port.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the pmproxy service (port 44322/TCP) to trusted hosts only using firewall rules. If pmproxy functionality is not required, disable the service. Disabling the service will prevent remote access to performance metrics via pmproxy. To disable the service, run: sudo systemctl stop pmproxy and sudo systemctl disable pmproxy. If firewalling, ensure to reload the firewall rules after making changes.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | pcp | Affected | ||
| Red Hat Enterprise Linux 6 | pcp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pcp | Affected | ||
| Red Hat Enterprise Linux 8 | pcp | Affected | ||
| Red Hat Enterprise Linux 9 | pcp | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
An unauthenticated remote attacker can bypass access controls by sendi ...
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
7.3 High
CVSS3