PT-2018-10949 · Phusion · Phusion Passenger

Published

2018-06-17

·

Updated

2022-05-14

·

CVE-2018-12026

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Phusion Passenger versions 5.3.x through 5.3.1
Description The issue allows malicious Passenger-managed applications to replace key files or directories in the spawning communication directory with symlinks during the spawning process. This can result in arbitrary reads and writes, leading to information disclosure and privilege escalation.
Recommendations For Phusion Passenger versions 5.3.x through 5.3.1, update to version 5.3.2 or later to resolve the issue.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12026
GHSA-7CV3-GVMC-8MQ5
OPENSUSE-SU-2024:11341-1

Affected Products

Phusion Passenger