Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phusion passenger vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2012-6135
RubyGems passenger 4.0.0 betas 1 and 2 allows remote malicious users to delete arbitrary files during the startup process.
Phusion Passenger 4.0.0
Redhat Openshift 1.0
5.3
CVSSv3
CVE-2018-12615
An issue exists in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger prior to 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering ...
Phusion Passenger
9.8
CVSSv3
CVE-2018-12026
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads an...
Phusion Passenger
8.8
CVSSv3
CVE-2018-12027
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the paren...
Phusion Passenger
7.8
CVSSv3
CVE-2018-12028
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious appl...
Phusion Passenger
7
CVSSv3
CVE-2018-12029
A race condition in the nginx module in Phusion Passenger 3.x up to and including 5.x prior to 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink aft...
Phusion Passenger
Debian Debian Linux 8.0
4.7
CVSSv3
CVE-2017-16355
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from th...
Phusion Passenger
Debian Debian Linux 9.0
7.8
CVSSv3
CVE-2016-10345
In Phusion Passenger prior to 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local malicious users to gain the privileges of the passenger user.
Phusion Passenger
3.7
CVSSv3
CVE-2015-7519
agent/Core/Controller/SendRequest.cpp in Phusion Passenger prior to 4.0.60 and 5.0.x prior to 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote malicious users to spoof headers passed to applications by using an _ (undersc...
Phusionpassenger Phusion Passenger 5.0.14
Phusionpassenger Phusion Passenger 5.0.13
Phusionpassenger Phusion Passenger 5.0.6
Phusionpassenger Phusion Passenger 5.0.19
Phusionpassenger Phusion Passenger 5.0.18
Phusionpassenger Phusion Passenger 5.0.17
Phusionpassenger Phusion Passenger 5.0.10
Phusionpassenger Phusion Passenger 5.0.9
Phusionpassenger Phusion Passenger 5.0.2
Phusionpassenger Phusion Passenger 5.0.1
Phusionpassenger Phusion Passenger 5.0.16
Phusionpassenger Phusion Passenger 5.0.15
Phusionpassenger Phusion Passenger 5.0.8
Phusionpassenger Phusion Passenger 5.0.7
Phusionpassenger Phusion Passenger 5.0.0
Phusionpassenger Phusion Passenger 5.0.21
Phusionpassenger Phusion Passenger 5.0.20
Phusionpassenger Phusion Passenger 5.0.12
Phusionpassenger Phusion Passenger 5.0.11
Phusionpassenger Phusion Passenger 5.0.4
Phusionpassenger Phusion Passenger 5.0.3
Phusionpassenger Phusion Passenger
NA
CVE-2014-1831
Phusion Passenger prior to 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
Phusion Passenger
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »