CVE-2012-6135 — Improper Input Validation in Passenger
Severity
7.5HIGHNVD
EPSS
1.3%
top 20.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateApr 23
Description
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Red Hat▶
rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes↗2013-02-17
💬Community
3Bugzilla▶
CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes↗2013-03-05
Bugzilla▶
CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes [fedora-all]↗2013-03-05
Bugzilla▶
CVE-2012-6135 rubygem-passenger: untrusted apps Security check socket filenames reported by spawned application processes [epel-6]↗2013-03-05