7.5
CVSSv2

CVE-2018-12026

Published: 17/06/2018 Updated: 08/03/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

Vulnerable Product Search on Vulmon Subscribe to Product

phusion passenger

Vendor Advisories

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 53x before 532 allows such applications to replace key files or directories in the spawning communication directory with symlinks This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privile ...