CVE-2017-16355
published 2017-12-14CVE-2017-16355: In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is…
PriorityP424medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.36%
28.4th percentile
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | passenger | < passenger 5.0.30-1.1 (bookworm) | passenger 5.0.30-1.1 (bookworm) |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.0.30-1.1 | 5.0.30-1.1 |
| phusion | passenger | >= 0 < 5.1.11 | 5.1.11 |
| phusion | passenger | >= 0 < 5.0.27-2ubuntu0.1~esm1 | 5.0.27-2ubuntu0.1~esm1 |
| phusion | passenger | >= 5.0.10 < 5.1.10 | 5.1.10 |
| phusion | passenger | >= 5.0.10 < 5.1.11 | 5.1.11 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Phusion Passenger information disclosure
osv·2022-05-13
CVE-2017-16355 [MEDIUM] Phusion Passenger information disclosure
Phusion Passenger information disclosure
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
GHSA
Phusion Passenger information disclosure
ghsa·2022-05-13
CVE-2017-16355 [MEDIUM] CWE-200 Phusion Passenger information disclosure
Phusion Passenger information disclosure
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
OSV
passenger vulnerabilities
osv·2022-02-01·CVSS 4.7
CVE-2017-16355 [MEDIUM] passenger vulnerabilities
passenger vulnerabilities
It was discovered that Phusion Passenger incorrectly handled a file path in
the application root folder. An attacker could possibly use this issue to
read arbitrary files. (CVE-2017-16355)
It was discovered that Phusion Passenger had a race condition in the nginx
module that could be used to perform a symlink attack. An attacker could
possibly use this issue to escalate privileges. (CVE-2018-12029)
OSV
CVE-2017-16355: In agent/Core/SpawningKit/Spawner
osv·2017-12-14·CVSS 4.7
CVE-2017-16355 [MEDIUM] CVE-2017-16355: In agent/Core/SpawningKit/Spawner
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Ubuntu
Phusion Passenger vulnerabilities
vendor_ubuntu·2022-02-01·CVSS 4.7
CVE-2017-16355 [MEDIUM] Phusion Passenger vulnerabilities
Title: Phusion Passenger vulnerabilities
Summary: Several security issues were fixed in Phusion Passenger.
It was discovered that Phusion Passenger incorrectly handled a file path in
the application root folder. An attacker could possibly use this issue to
read arbitrary files. (CVE-2017-16355)
It was discovered that Phusion Passenger had a race condition in the nginx
module that could be used to perform a symlink attack. An attacker could
possibly use this issue to escalate privileges. (CVE-2018-12029)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
passenger: arbitrary file read via REVISION symlink
vendor_redhat·2017-10-16·CVSS 4.7
CVE-2017-16355 [MEDIUM] passenger: arbitrary file read via REVISION symlink
passenger: arbitrary file read via REVISION symlink
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Package: ruby193-rubygem-passenger (Red Hat Ceph Storage 1.3) - Will not fix
Package: rubygem-passenger (Red Hat Ceph Storage 1.3) - Will not fix
Package: ruby193-rubygem-passeger (Red Hat Satellite 6) - Not affected
Package: rubygem-passenger (Red Hat Satellite 6) - Not affected
Package: rh-passenger40-passenger (Red Hat Software Collections) - Will not fix
Debian
CVE-2017-16355: passenger - In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passen...
vendor_debian·2017·CVSS 4.7
CVE-2017-16355 [MEDIUM] CVE-2017-16355: passenger - In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passen...
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Scope: local
bookworm: resolved (fixed in 5.0.30-1.1)
bullseye: resolved (fixed in 5.0.30-1.1)
forky: resolved (fixed in 5.0.30-1.1)
sid: resolved (fixed in 5.0.30-1.1)
trixie: resolved (fixed in 5.0.30-1.1)
No detection rules found.
No public exploits indexed.
https://blog.phusion.nl/2017/10/13/passenger-security-advisory-5-1-11/https://github.com/phusion/passenger/commit/4043718264095cde6623c2cbe8c644541036d7bfhttps://seclists.org/bugtraq/2019/Mar/34https://www.debian.org/security/2019/dsa-4415https://blog.phusion.nl/2017/10/13/passenger-security-advisory-5-1-11/https://github.com/phusion/passenger/commit/4043718264095cde6623c2cbe8c644541036d7bfhttps://seclists.org/bugtraq/2019/Mar/34https://www.debian.org/security/2019/dsa-4415
2017-12-14
Published