PT-2017-3780 · Phusion+2 · Phusion Passenger+2
Published
2017-10-11
·
Updated
2022-05-13
·
CVE-2017-16355
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Phusion Passenger versions 5.1.10
Description
The issue allows an attacker to list the contents of arbitrary files on a system by creating a symbolic link from the REVISION file in the application root folder to a file of choice and then querying
passenger-status --show=xml. This can potentially lead to unauthorized access to confidential data. The vulnerability is related to the REVISION file and can be exploited when Passenger is running as root.Recommendations
For Phusion Passenger version 5.1.10, update to Passenger Open Source 5.1.11 or Passenger Enterprise 5.1.10 to resolve the issue. As a temporary workaround, consider restricting access to the
passenger-status command and limiting the ability to create symbolic links in the application root folder.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phusion Passenger
Suse
Ubuntu