VDB
Sign up
LOW

GHSA-qw8w-2xcp-xg59

Insecure use of temporary files in Phusion passenger

Quick fix

GHSA-qw8w-2xcp-xg59 — passenger: upgrade to the fixed version with the command below.

bundle update passenger

Details

Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/passenger
Introduced in: 4.0.37Fixed in: 4.0.38
Fixbundle update passenger

References