ALSA-2024:2566
Dashboard / Vulnerabilities / ALSA-2024:2566
Summary: Important: pcp security, bug fix, and enhancement update
Details: Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems. Security Fix(es): * pcp: exposure of the redis server backend allows remote command execution via pmproxy (CVE-2024-3019) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:2566, https://access.redhat.com/security/cve/CVE-2024-3019, https://bugzilla.redhat.com/2271898, https://errata.almalinux.org/9/ALSA-2024-2566.html
Affected packages
Package
Name: pcp
Purl: pkg:rpm/almalinux/pcp
Affected ranges
Type: ECOSYSTEM
Events:
