REDHAT-BUG-2271898: High severity Performance Co-Pilot PCP vulnerability
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user.
This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface.
This issue affects PCP versions 4.3.4 and newer.
Upstream patch: https://github.com/performancecopilot/pcp/commit/3bde240a2acc85e63e2f7813330713dd9b59386e
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2271898?
The severity of REDHAT-BUG-2271898 is critical due to the potential for remote command execution.
How do I fix REDHAT-BUG-2271898?
To fix REDHAT-BUG-2271898, ensure that pmproxy is not running or update to a patched version of Performance Co-Pilot PCP.
What systems are affected by REDHAT-BUG-2271898?
REDHAT-BUG-2271898 affects Performance Co-Pilot PCP version 4.3.4 and potentially later versions if misconfigured.
Can REDHAT-BUG-2271898 be exploited remotely?
REDHAT-BUG-2271898 can be exploited remotely if pmproxy is running with the default configuration.
What are the risks associated with REDHAT-BUG-2271898?
The risks associated with REDHAT-BUG-2271898 include unauthorized remote access and potential system compromise.