CVE-2016-10345
HIGHPhusion Passenger < 5.1.0 - Privilege Escalation via Predictable /tmp Filename
Title source: llmDescription
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
References (2)
Core 2
Core References
Patch x_refsource_confirm
https://github.com/phusion/passenger/commit/e5b4b0824d6b648525b4bf63d9fa37e5beeae441
Patch, Release Notes x_refsource_confirm
https://github.com/phusion/passenger/blob/stable-5.1/CHANGELOG
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
19.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (2)
phusion/passenger
< 5.0.30
rubygems/passenger
0 - 5.1.0RubyGems
Published
Apr 18, 2017
Tracked Since
Feb 18, 2026