Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phusion passenger vulnerabilities and exploits
(subscribe to this query)
570
VMScore
CVE-2012-6135
RubyGems passenger 4.0.0 betas 1 and 2 allows remote malicious users to delete arbitrary files during the startup process.
Phusion Passenger 4.0.0
Redhat Openshift 1.0
445
VMScore
CVE-2018-12615
An issue exists in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger prior to 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering ...
Phusion Passenger
668
VMScore
CVE-2018-12026
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads an...
Phusion Passenger
605
VMScore
CVE-2018-12028
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious appl...
Phusion Passenger
578
VMScore
CVE-2018-12027
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the paren...
Phusion Passenger
392
VMScore
CVE-2018-12029
A race condition in the nginx module in Phusion Passenger 3.x up to and including 5.x prior to 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink aft...
Phusion Passenger
Debian Debian Linux 8.0
107
VMScore
CVE-2017-16355
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from th...
Phusion Passenger
Debian Debian Linux 9.0
409
VMScore
CVE-2016-10345
In Phusion Passenger prior to 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local malicious users to gain the privileges of the passenger user.
Phusion Passenger
383
VMScore
CVE-2015-7519
agent/Core/Controller/SendRequest.cpp in Phusion Passenger prior to 4.0.60 and 5.0.x prior to 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote malicious users to spoof headers passed to applications by using an _ (undersc...
Phusionpassenger Phusion Passenger 5.0.14
Phusionpassenger Phusion Passenger 5.0.13
Phusionpassenger Phusion Passenger 5.0.6
Phusionpassenger Phusion Passenger 5.0.19
Phusionpassenger Phusion Passenger 5.0.18
Phusionpassenger Phusion Passenger 5.0.17
Phusionpassenger Phusion Passenger 5.0.10
Phusionpassenger Phusion Passenger 5.0.9
Phusionpassenger Phusion Passenger 5.0.2
Phusionpassenger Phusion Passenger 5.0.1
Phusionpassenger Phusion Passenger 5.0.16
Phusionpassenger Phusion Passenger 5.0.15
Phusionpassenger Phusion Passenger 5.0.8
Phusionpassenger Phusion Passenger 5.0.7
Phusionpassenger Phusion Passenger 5.0.0
Phusionpassenger Phusion Passenger 5.0.21
Phusionpassenger Phusion Passenger 5.0.20
Phusionpassenger Phusion Passenger 5.0.12
Phusionpassenger Phusion Passenger 5.0.11
Phusionpassenger Phusion Passenger 5.0.4
Phusionpassenger Phusion Passenger 5.0.3
Phusionpassenger Phusion Passenger
187
VMScore
CVE-2014-1832
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.
Phusion Passenger
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
man-in-the-middle
CVE-2024-34558
CVE-2024-32674
CVE-2024-34351
XPath injection
CVE-2023-45866
CVE-2024-25528
CVE-2024-25517
path traversal
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »