Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phusion vulnerabilities and exploits
(subscribe to this query)
570
VMScore
CVE-2012-6135
RubyGems passenger 4.0.0 betas 1 and 2 allows remote malicious users to delete arbitrary files during the startup process.
Phusion Passenger 4.0.0
Redhat Openshift 1.0
445
VMScore
CVE-2018-12615
An issue exists in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger prior to 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering ...
Phusion Passenger
578
VMScore
CVE-2018-12027
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the paren...
Phusion Passenger
605
VMScore
CVE-2018-12028
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious appl...
Phusion Passenger
392
VMScore
CVE-2018-12029
A race condition in the nginx module in Phusion Passenger 3.x up to and including 5.x prior to 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink aft...
Phusion Passenger
Debian Debian Linux 8.0
668
VMScore
CVE-2018-12026
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads an...
Phusion Passenger
107
VMScore
CVE-2017-16355
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from th...
Phusion Passenger
Debian Debian Linux 9.0
409
VMScore
CVE-2016-10345
In Phusion Passenger prior to 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local malicious users to gain the privileges of the passenger user.
Phusion Passenger
383
VMScore
CVE-2015-7519
agent/Core/Controller/SendRequest.cpp in Phusion Passenger prior to 4.0.60 and 5.0.x prior to 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote malicious users to spoof headers passed to applications by using an _ (undersc...
Phusionpassenger Phusion Passenger 5.0.14
Phusionpassenger Phusion Passenger 5.0.13
Phusionpassenger Phusion Passenger 5.0.6
Phusionpassenger Phusion Passenger 5.0.19
Phusionpassenger Phusion Passenger 5.0.18
Phusionpassenger Phusion Passenger 5.0.17
Phusionpassenger Phusion Passenger 5.0.10
Phusionpassenger Phusion Passenger 5.0.9
Phusionpassenger Phusion Passenger 5.0.2
Phusionpassenger Phusion Passenger 5.0.1
Phusionpassenger Phusion Passenger 5.0.16
Phusionpassenger Phusion Passenger 5.0.15
Phusionpassenger Phusion Passenger 5.0.8
Phusionpassenger Phusion Passenger 5.0.7
Phusionpassenger Phusion Passenger 5.0.0
Phusionpassenger Phusion Passenger 5.0.21
Phusionpassenger Phusion Passenger 5.0.20
Phusionpassenger Phusion Passenger 5.0.12
Phusionpassenger Phusion Passenger 5.0.11
Phusionpassenger Phusion Passenger 5.0.4
Phusionpassenger Phusion Passenger 5.0.3
Phusionpassenger Phusion Passenger
187
VMScore
CVE-2014-1831
Phusion Passenger prior to 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
Phusion Passenger
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »