CyberSec.Space Logo
Back to CVE Browser

CVE-2018-12026

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1750%
EPSS Percentile37.53th
PublishedJun 17, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

Affected Platforms (CPE)

πŸ“¦
Phusion

Passenger

>= 5.3.0 and < 5.3.2

References & Advisories

Related Vulnerabilities