HIGH7.5
GHSA-8mw8-j583-vqfg
RubyGems passenger gem allows remote attackers to delete files
Quick fix
GHSA-8mw8-j583-vqfg — passenger: upgrade to the fixed version with the command below.
bundle update passengerDetails
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Affects both open source and Enterprise versions (4.0.0.beta1, 4.0.0.beta2).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2012-6135[ADVISORY]
- https://github.com/phusion/passenger/commit/8c6693e0818772c345c979840d28312c2edd4ba4[WEB]
- https://github.com/phusion/passenger/commit/8c6693e0818772c345c979840d28312c2edd4ba4#commitcomment-2643541[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82533[WEB]
- https://github.com/phusion/passenger[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2012-6135.yml[WEB]
- https://security-tracker.debian.org/tracker/CVE-2012-6135[WEB]
- https://web.archive.org/web/20200918164919/https://old.blog.phusion.nl/2013/03/05/phusion-passenger-4-0-beta-1-and-2-arbitrary-file-deletion-vulnerability[WEB]
- http://www.openwall.com/lists/oss-security/2013/03/02/1[WEB]