Untriaged
Permalink
CVE-2024-3019
8.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): ADJACENT_NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Pcp: exposure of the redis server backend allows remote command execution via pmproxy
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.
References
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry
- RHBZ#2271898 issue-tracking x_refsource_REDHAT
- RHSA-2024:2566 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3264 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3321 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3322 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3323 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3324 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3325 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3392 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-3019 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2271898 issue-tracking x_refsource_REDHAT x_transferred
Affected products
pcp
- *
- *
Matching in nixpkgs
pkgs.pcp
Command line peer-to-peer data transfer tool based on libp2p
-
nixos-unstable -
- nixpkgs-unstable 0.4.0
pkgs.ncmpcpp
Featureful ncurses based MPD client inspired by ncmpc
-
nixos-unstable -
- nixpkgs-unstable 0.10.1
pkgs.libamqpcpp
Library for communicating with a RabbitMQ server
-
nixos-unstable -
- nixpkgs-unstable 4.3.27
pkgs.python312Packages.pcpp
C99 preprocessor written in pure Python
-
nixos-unstable -
- nixpkgs-unstable 1.30
pkgs.python313Packages.pcpp
C99 preprocessor written in pure Python
-
nixos-unstable -
- nixpkgs-unstable 1.30
Package maintainers
-
@MikePlayle Mike Playle <mike@mythik.co.uk>
-
@lovek323 Jason O'Conal <jason@oconal.id.au>
-
@k0ral Koral <koral@mailoo.org>
-
@MatthewCroughan Matthew Croughan <matt@croughan.sh>
-
@Rakesh4G Rakesh Gupta <rakeshgupta4u@gmail.com>