Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-1.ova and later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
CWE-1393
Vulnerability Title
Percona PMM Server 安全漏洞
Vulnerability Description
Percona PMM Server是Percona公司的一个针对 MySQL、PostgreSQL、MongoDB 和 ProxySQL 的开源数据库可观察性、监控和管理工具。 Percona PMM Server 3.0.0-1.ova之前版本存在安全漏洞,该漏洞源于默认服务账户凭据可能导致SSH访问和敏感数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A