PT-2017-3780 · Phusion+2 · Phusion Passenger+2

Published

2017-10-11

·

Updated

2022-05-13

·

CVE-2017-16355

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Phusion Passenger versions 5.1.10
Description The issue allows an attacker to list the contents of arbitrary files on a system by creating a symbolic link from the REVISION file in the application root folder to a file of choice and then querying passenger-status --show=xml. This can potentially lead to unauthorized access to confidential data. The vulnerability is related to the REVISION file and can be exploited when Passenger is running as root.
Recommendations For Phusion Passenger version 5.1.10, update to Passenger Open Source 5.1.11 or Passenger Enterprise 5.1.10 to resolve the issue. As a temporary workaround, consider restricting access to the passenger-status command and limiting the ability to create symbolic links in the application root folder.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01588
CVE-2017-16355
DSA-4415-1
GHSA-CV3F-PX9R-54HM
SUSE-SU-2018:0262-1
USN-5261-1

Affected Products

Phusion Passenger
Suse
Ubuntu