Описание
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
Отчет
Moderate: The pmproxy logger servlet in PCP is susceptible to a path traversal vulnerability, enabling an unauthenticated remote attacker to create arbitrary files and directories. This can lead to a denial of service or other impacts on systems where pmproxy is exposed on TCP port 44322, as the logger servlet is unconditionally active.
Меры по смягчению последствий
To mitigate this issue, restrict network access to TCP port 44322, which is used by the pmproxy service. This can be achieved by configuring a firewall to block incoming connections to this port. Alternatively, if the pmproxy service is not essential for your environment, it can be disabled. To disable the pmproxy service: sudo systemctl stop pmproxy sudo systemctl disable pmproxy Warning: Disabling pmproxy may impact the functionality of Performance Co-Pilot components that rely on it for data collection and logging.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | pcp | Affected | ||
| Red Hat Enterprise Linux 6 | pcp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pcp | Out of support scope | ||
| Red Hat Enterprise Linux 8 | pcp | Fix deferred | ||
| Red Hat Enterprise Linux 9 | pcp | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
An unauthenticated remote attacker can exploit a path traversal vulner ...
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
EPSS
5.3 Medium
CVSS3