PT-2024-2710 · Cockpit+10 · Cockpit+10

Guilherme De Almeida Suckevicz

·

Published

2024-03-27

·

Updated

2025-09-16

·

CVE-2024-3019

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Performance Co-Pilot (PCP) versions 4.3.4 and newer
Description The issue is related to the pmproxy component of the Performance Co-Pilot (PCP) software, which is used for monitoring and visualizing performance. It involves the exposure of information in an error data area, potentially allowing a remote attacker to execute arbitrary commands. The default pmproxy configuration exposes the Redis server backend to the local network, enabling remote command execution with the privileges of the Redis user. This can only be exploited when pmproxy is running, which is not the default state and requires manual startup, often from the 'Metrics settings' page of the Cockpit web interface.
Recommendations For PCP versions 4.3.4 and newer, consider disabling the pmproxy service until a patch is available to prevent exploitation. Restrict access to the Redis server backend to minimize the risk of remote command execution. As a temporary workaround, avoid starting the pmproxy service from the 'Metrics settings' page of the Cockpit web interface unless necessary. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

ALSA-2024:2566
ALSA-2024:3264
BDU:2024-02823
CESA-2024_3264
CVE-2024-3019
INFSA-2024_2566
INFSA-2024_3264
OESA-2024-1435
OESA-2024-1436
OESA-2024-1437
OESA-2024-1495
OPENSUSE-SU-2024_3533-1
RHSA-2024:2566
RHSA-2024:3264
RHSA-2024:3321
RHSA-2024:3322
RHSA-2024:3323
RHSA-2024:3324
RHSA-2024:3325
RHSA-2024:3392
RHSA-2024_2566
RHSA-2024_3264
RLSA-2024:2566
RLSA-2024:3264
SUSE-SU-2024:3533-1
SUSE-SU-2024:3976-1
SUSE-SU-2025:03233-1
SUSE-SU-2025:20133-1
SUSE-SU-2025:20235-1
SUSE-SU-2025_03233-1

Affected Products

Almalinux
Centos
Cockpit
Debian
Performance Co-Pilot
Red Hat
Red Os
Redis
Rocky Linux
Suse
Zvirt Node