6.8
CVSSv2

CVE-2018-12028

Published: 17/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x prior to 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.

Vulnerable Product Search on Vulmon Subscribe to Product

phusion passenger

Vendor Advisories

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 53x before 532 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager If the malicious application then generates an error, it would cause Passenger's process manager t ...