<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:48:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2566 — Important: pcp security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2566</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pcp, AlmaLinux:9: pcp-conf, AlmaLinux:9: pcp-devel, AlmaLinux:9: pcp-doc, AlmaLinux:9: pcp-export-pcp2elasticsearch, AlmaLinux:9: pcp-export-pcp2graphite, AlmaLinux:9: pcp-export-pcp2influxdb, AlmaLinux:9: pcp-export-pcp2json, AlmaLinux:9: pcp-export-pcp2spark, AlmaLinux:9: pcp-export-pcp2xml and 94 more&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pcp: exposure of the redis server backend allows remote command execution via pmproxy (CVE-2024-3019)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pcp, AlmaLinux:9: pcp-conf, AlmaLinux:9: pcp-devel, AlmaLinux:9: pcp-doc, AlmaLinux:9: pcp-export-pcp2elasticsearch, AlmaLinux:9: pcp-export-pcp2graphite, AlmaLinux:9: pcp-export-pcp2influxdb, AlmaLinux:9: pcp-export-pcp2json, AlmaLinux:9: pcp-export-pcp2spark, AlmaLinux:9: pcp-export-pcp2xml and 94 more&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pcp: exposure of the redis server backend allows remote command execution via pmproxy (CVE-2024-3019)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2566</guid>
    </item>
    <item>
      <title>bdu:2024-02823</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02823</link>
      <description>bdu:2024-02823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02823</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</link>
      <description>certfr-2024-avi-0579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</guid>
    </item>
    <item>
      <title>EUVD-2026-261409</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261409</link>
      <description>EUVD-2026-261409</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261409</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3019</link>
      <description>&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3019</guid>
    </item>
    <item>
      <title>GHSA-g58w-wr93-q367</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g58w-wr93-q367</link>
      <description>&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g58w-wr93-q367</guid>
    </item>
    <item>
      <title>gsd-2024-3019</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3019</link>
      <description>gsd-2024-3019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3019</guid>
    </item>
    <item>
      <title>OESA-2024-1435 — pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: pcp&lt;/p&gt;
&lt;p&gt;PCP provides a range of services that may be used to monitor and manage system performance. These services are distributed and scalable to accommodate the most complex system configurations and performance problems.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;amp;apos;Metrics settings&amp;amp;apos; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.(CVE-2024-3019)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: pcp&lt;/p&gt;
&lt;p&gt;PCP provides a range of services that may be used to monitor and manage system performance. These services are distributed and scalable to accommodate the most complex system configurations and performance problems.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;amp;apos;Metrics settings&amp;amp;apos; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.(CVE-2024-3019)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1435</guid>
    </item>
    <item>
      <title>RHSA-2024:2566 — Red Hat Security Advisory: pcp security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2566</link>
      <description>&lt;p&gt;pcp: exposure of the redis server backend allows remote command execution via pmproxy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pcp: exposure of the redis server backend allows remote command execution via pmproxy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2566</guid>
    </item>
    <item>
      <title>RHSA-2024:3321 — Red Hat Security Advisory: pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3321</link>
      <description>&lt;p&gt;pcp: exposure of the redis server backend allows remote command execution via pmproxy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pcp: exposure of the redis server backend allows remote command execution via pmproxy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3321</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3533-1 — Security update for pcp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3533-1</link>
      <description>&lt;p&gt;Security update for pcp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for pcp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3533-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-3019</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3019</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:25.10: pcp, Ubuntu:26.04:LTS: pcp&lt;/p&gt;
&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:25.10: pcp, Ubuntu:26.04:LTS: pcp&lt;/p&gt;
&lt;p&gt;A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;#39;Metrics settings&amp;#39; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1003 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</guid>
    </item>
  </channel>
</rss>
