ADVISORIES
GEM
SEVERITY
CVSS v3.x: 7.8 (High)
CVSS v2.0: 4.6 (Medium)
PATCHED VERSIONS
- >= 5.1.0
DESCRIPTION
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.