Debian Passenger vulnerabilities

13 known vulnerabilities affecting debian/passenger.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW11

Vulnerabilities

Page 1 of 1
CVE-2025-26803LOWCVSS 5.3fixed in passenger 6.0.26+ds-1 (forky)2025
CVE-2025-26803 [MEDIUM] CVE-2025-26803: passenger - The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows ... The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 6.0.26+ds-1) sid: resolved (fixed in 6.0.26+ds-1) trixie: resolved (fixed in 6.0.26+ds-1)
debian
CVE-2018-12029LOWCVSS 7.0fixed in passenger 5.0.30-1.1 (bookworm)2018
CVE-2018-12029 [HIGH] CVE-2018-12029: passenger - A race condition in the nginx module in Phusion Passenger 3.x through 5.x before... A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned vi
debian
CVE-2018-12026LOWCVSS 9.82018
CVE-2018-12026 [CRITICAL] CVE-2018-12026: passenger - During the spawning of a malicious Passenger-managed application, SpawningKit in... During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalatio
debian
CVE-2018-12615LOWCVSS 5.32018
CVE-2018-12615 [MEDIUM] CVE-2018-12615: passenger - An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp ... An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Scope: local bookworm: resolved bullseye: resolved forky: resolved
debian
CVE-2018-12027LOWCVSS 8.82018
CVE-2018-12027 [HIGH] CVE-2018-12027: passenger - An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x ... An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's
debian
CVE-2018-12028LOWCVSS 7.82018
CVE-2018-12028 [HIGH] CVE-2018-12028: passenger - An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.... An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said repo
debian
CVE-2017-16355MEDIUMCVSS 4.7fixed in passenger 5.0.30-1.1 (bookworm)2017
CVE-2017-16355 [MEDIUM] CVE-2017-16355: passenger - In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passen... In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=x
debian
CVE-2016-10345LOWCVSS 7.8fixed in passenger 6.0.10-1 (bookworm)2016
CVE-2016-10345 [HIGH] CVE-2016-10345: passenger - In Phusion Passenger before 5.1.0, a known /tmp filename was used during passeng... In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user. Scope: local bookworm: resolved (fixed in 6.0.10-1) bullseye: open forky: resolved (fixed in 6.0.10-1) sid: resolved (fixed in 6.0.10-1) trixie: resolved (fixed in 6.0.10-
debian
CVE-2015-7519LOWCVSS 3.7fixed in passenger 5.0.22-1 (bookworm)2015
CVE-2015-7519 [LOW] CVE-2015-7519: passenger - agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0... agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User head
debian
CVE-2014-1831LOWCVSS 2.1fixed in passenger 4.0.37-1 (bookworm)2014
CVE-2014-1831 [LOW] CVE-2014-1831: passenger - Phusion Passenger before 4.0.37 allows local users to write to certain files and... Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. Scope: local bookworm: resolved (fixed in 4.0.37-1) bullseye: resolved (fixed in 4.0.37-1) forky: resolved (fixed in 4.0.37-1) sid: resolved (fixed in 4.0.37-1) trixie: resolved (fixed in 4.0.37-1)
debian
CVE-2014-1832LOWCVSS 2.12014
CVE-2014-1832 [LOW] CVE-2014-1832: passenger - Phusion Passenger 4.0.37 allows local users to write to certain files and direct... Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2013-4136MEDIUMCVSS 4.4fixed in passenger 3.0.13debian-1.2 (bookworm)2013
CVE-2013-4136 [MEDIUM] CVE-2013-4136: passenger - ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby al... ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/. Scope: local bookworm: resolved (fixed in 3.0.13debian-1.2) bullseye: resolved (fixed in 3.0.13debian-1.2) forky: resolved
debian
CVE-2008-7220LOWCVSS 7.5fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2008
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before... Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. Scope: local bullseye: resolved (fixed in 1:1.6.2.0~rc3-1) sid: resolved (fixed in 1:1.6.2.0~rc3-1)
debian