cbcvebase.
CVE-2018-12029
published 2018-06-17

CVE-2018-12029: A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard…

PriorityP431high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.28%
19.8th percentile
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpassenger< passenger 5.0.30-1.1 (bookworm)passenger 5.0.30-1.1 (bookworm)
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.30-1.15.0.30-1.1
phusionpassenger>= 0 < 5.0.27-2ubuntu0.1~esm15.0.27-2ubuntu0.1~esm1
phusionpassenger>= 3.0.0 < 5.3.25.3.2
phusionpassenger>= 3.0.0 < 5.3.25.3.2

CVSS provenance

nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.