Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cv3-gvmc-8mq5

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

Пакеты

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

>= 5.3.0, < 5.3.2

5.3.2

EPSS

Процентиль: 78%
0.01123
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

CVSS3: 7.1
redhat
больше 7 лет назад

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

CVSS3: 9.8
nvd
больше 7 лет назад

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

CVSS3: 9.8
debian
больше 7 лет назад

During the spawning of a malicious Passenger-managed application, Spaw ...

EPSS

Процентиль: 78%
0.01123
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-59