cbcvebase.
CVE-2017-16355
published 2017-12-14

CVE-2017-16355: In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is…

PriorityP424medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.36%
28.4th percentile
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpassenger< passenger 5.0.30-1.1 (bookworm)passenger 5.0.30-1.1 (bookworm)
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.1.115.1.11
phusionpassenger>= 0 < 5.0.27-2ubuntu0.1~esm15.0.27-2ubuntu0.1~esm1
phusionpassenger>= 5.0.10 < 5.1.105.1.10
phusionpassenger>= 5.0.10 < 5.1.115.1.11

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.