Issued at: 2024-05-10
Updated at: 2024-05-10
Synopsis
Important: pcp security, bug fix, and enhancement update
Description
Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.
Security Fix(es):
* pcp: exposure of the redis server backend allows remote command execution via pmproxy (CVE-2024-3019)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.