CyberSec.Space Logo
CVEブラウザに戻る

CVE-2018-12026

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1750%
EPSS Percentile37.53th
Published2018年6月17日
Last Modified2024年11月21日

Vulnerability Description

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

Affected Platforms (CPE)

📦
Phusion

Passenger

>= 5.3.0 and < 5.3.2

References & Advisories

関連する脆弱性情報