A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade passenger | Feb 19, 2019 | Jun 17, 2018 |
| Gentoo Linux | — | Upgrade www-apache/passenger. | Jul 23, 2018 | Jun 17, 2018 |
| Suse | — | Upgrade rubygem-passenger-apache2Upgrade rubygem-passengerUpgrade ruby2.1-rubygem-passenger | Feb 4, 2022 | Jun 17, 2018 |
| Ubuntu | — | Upgrade passenger (Ubuntu Pro)Upgrade libapache2-mod-passenger (Ubuntu Pro) | Mar 22, 2023 | Jun 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub