CyberSec.Space Logo
返回 CVE 浏览器

CVE-2018-12026

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1750%
EPSS Percentile37.53th
Published2018年6月17日
Last Modified2024年11月21日

Vulnerability Description

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

Affected Platforms (CPE)

📦
Phusion

Passenger

>= 5.3.0 and < 5.3.2

References & Advisories

相关漏洞威胁