VDB
Sign up
MEDIUM

GHSA-w6rc-q387-vpgq

insecure temporary directory usage in passenger

Quick fix

GHSA-w6rc-q387-vpgq — passenger: upgrade to the fixed version with the command below.

bundle update passenger

Details

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/passenger
Introduced in: 0Fixed in: 4.0.6
Fixbundle update passenger

References