The remote Debian host is missing a security-related update.
Cedric Buissart from Red Hat discovered an information disclosure bug in pcs, a pacemaker command line interface and GUI. The REST interface normally doesn't allow passing --debug parameter to prevent information leak, but the check wasn't sufficient.
Upgrade the pcs packages. For the stable distribution (stretch), this problem has been fixed in version 0.9.155+dfsg-2+deb9u1.