CVE-2018-12028
published 2018-06-17CVE-2018-12028: An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon…
PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.90%
56.0th percentile
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | passenger | — | — |
| phusion | passenger | >= 0 < 6.0.10-3build1 | 6.0.10-3build1 |
| phusion | passenger | >= 5.3.0 < 5.3.2 | 5.3.2 |
| phusion | passenger | >= 5.3.0 < 5.3.2 | 5.3.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Access Control in Phusion Passenger
osv·2022-05-13
CVE-2018-12028 [HIGH] Incorrect Access Control in Phusion Passenger
Incorrect Access Control in Phusion Passenger
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
GHSA
Incorrect Access Control in Phusion Passenger
ghsa·2022-05-13
CVE-2018-12028 [HIGH] CWE-732 Incorrect Access Control in Phusion Passenger
Incorrect Access Control in Phusion Passenger
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
OSV
CVE-2018-12028: An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5
osv·2018-06-17·CVSS 7.8
CVE-2018-12028 [HIGH] CVE-2018-12028: An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
Red Hat
passenger: Improper access control in SpawningKit can allow malicious child processes to kill arbitrary processes
vendor_redhat·2018-06-05·CVSS 7.8
CVE-2018-12028 [HIGH] CWE-284 passenger: Improper access control in SpawningKit can allow malicious child processes to kill arbitrary processes
passenger: Improper access control in SpawningKit can allow malicious child processes to kill arbitrary processes
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
Package: rubygem-passenger (Red Hat Ceph Storage 1.3) - Not affected
Package: rubygem-passenger (Red Hat Satellite 6) - Not affected
Package: rubygem-passenger (Red Hat Update Infrastructure 3 for Cloud Providers) - Not affected
Debian
CVE-2018-12028: passenger - An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5....
vendor_debian·2018·CVSS 7.8
CVE-2018-12028 [HIGH] CVE-2018-12028: passenger - An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5....
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2018-06-17
Published