CVE-2018-12027
published 2018-06-17CVE-2018-12027: An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a…
PriorityP340high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.09%
61.9th percentile
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | passenger | — | — |
| phusion | passenger | >= 0 < 6.0.10-3build1 | 6.0.10-3build1 |
| phusion | passenger | >= 5.3.0 < 5.3.2 | 5.3.2 |
| phusion | passenger | >= 5.3.0 < 5.3.2 | 5.3.2 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insecure Permissions in Phusion Passenger
osv·2022-05-13
CVE-2018-12027 [HIGH] Insecure Permissions in Phusion Passenger
Insecure Permissions in Phusion Passenger
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
GHSA
Insecure Permissions in Phusion Passenger
ghsa·2022-05-13
CVE-2018-12027 [HIGH] CWE-200 Insecure Permissions in Phusion Passenger
Insecure Permissions in Phusion Passenger
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
OSV
CVE-2018-12027: An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5
osv·2018-06-17·CVSS 8.8
CVE-2018-12027 [HIGH] CVE-2018-12027: An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Red Hat
passenger: Insecure permissions in SpawningKit can allow for redirection of traffic under certain configurations
vendor_redhat·2018-06-05·CVSS 8.8
CVE-2018-12027 [HIGH] CWE-284 passenger: Insecure permissions in SpawningKit can allow for redirection of traffic under certain configurations
passenger: Insecure permissions in SpawningKit can allow for redirection of traffic under certain configurations
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Package: rubygem-passenger (Red Hat Ceph Storage 1.3) - Not affected
Package: rubygem-passenger (Red Hat Satellite 6)
Debian
CVE-2018-12027: passenger - An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x ...
vendor_debian·2018·CVSS 8.8
CVE-2018-12027 [HIGH] CVE-2018-12027: passenger - An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x ...
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2018-06-17
Published