In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-4415-1 | passenger security update |
![]() |
EUVD-2022-3633 | In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml. |
![]() |
GHSA-cv3f-px9r-54hm | Phusion Passenger information disclosure |
![]() |
USN-5261-1 | Phusion Passenger vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:20:05.642Z
Reserved: 2017-11-01T00:00:00
Link: CVE-2017-16355

No data.

Status : Deferred
Published: 2017-12-14T22:29:00.210
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-16355


No data.