RubySec

Providing security resources for the Ruby community

CVE-2016-10345 (passenger): Predictable tmp File Path Vulnerability in Phusion Passenger

ADVISORIES

GEM

passenger

SEVERITY

CVSS v3.x: 7.8 (High)

CVSS v2.0: 4.6 (Medium)

PATCHED VERSIONS

  • >= 5.1.0

DESCRIPTION

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.