GHSA-whfx-877c-5p28

    Dashboard / Vulnerabilities / GHSA-whfx-877c-5p28

    GHSA-whfx-877c-5p28

    Published: 13 May 2022Last Modified: 16 Feb 2024

    Summary: Insecure Permissions in Phusion Passenger

    Details: An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.

    Affected packages

    Package

    Name: passenger

    Purl: pkg:gem/passenger

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.3.0
    Fixed -5.3.2

    Affected versions

    5.3.0
    5.3.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-whfx-877c-5p28 | CVE-DB