Описание
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
4.6 Medium
CVSS2
Дефекты
Связанные уязвимости
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby al ...
EPSS
4.6 Medium
CVSS2