An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5579 An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Github GHSA Github GHSA GHSA-whfx-877c-5p28 Insecure Permissions in Phusion Passenger
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:24:03.683Z

Reserved: 2018-06-07T00:00:00

Link: CVE-2018-12027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-17T20:29:00.417

Modified: 2024-11-21T03:44:26.810

Link: CVE-2018-12027

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-06-05T00:00:00Z

Links: CVE-2018-12027 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses