VYPR

Pmm

by Percona

Source repositories

CVEs (2)

  • CVE-2025-26701CriMar 11, 2025
    risk 0.65cvss 10.0epss 0.00

    An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and…

  • CVE-2023-34409CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made…