passenger
A modern web server and application server for Ruby, Python and Node.js, optimized for performance, low memory usage and ease of use.
Activity
- Latest release
- 3w ago
- Total releases
- 207
- Cadence
- ~42 days
- Last 12 months
- 9
Details
- First release
- Apr 10, 2008
| Version | Released | |
|---|---|---|
6.2.0
minor
| ||
6.1.8
patch
| ||
6.1.7
patch
| ||
6.1.6
patch
| ||
6.1.5
patch
| ||
6.1.4
patch
| ||
6.1.3
patch
| ||
6.1.2
patch
| ||
6.1.1
patch
| ||
6.1.0
minor
| ||
6.0.27
patch
| ||
6.0.26
patch
| ||
6.0.25
patch
1 CVE
CVE-2025-26803
GHSA-2cj2-qqxj-5m3r
BIT-passenger-2025-26803
BIT-passenger-apache-module-2025-26803
BIT-passenger-nginx-module-2025-26803
Feb 24, 2025
Phusion Passenger denial of service
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Affected versions
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
Fixed in
6.0.26
References
Updated Mar 02, 2025 · Source: OSV.dev | ||
6.0.24
patch
1 CVE
CVE-2025-26803
GHSA-2cj2-qqxj-5m3r
BIT-passenger-2025-26803
BIT-passenger-apache-module-2025-26803
BIT-passenger-nginx-module-2025-26803
Feb 24, 2025
Phusion Passenger denial of service
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Affected versions
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
Fixed in
6.0.26
References
Updated Mar 02, 2025 · Source: OSV.dev | ||
6.0.23
patch
1 CVE
CVE-2025-26803
GHSA-2cj2-qqxj-5m3r
BIT-passenger-2025-26803
BIT-passenger-apache-module-2025-26803
BIT-passenger-nginx-module-2025-26803
Feb 24, 2025
Phusion Passenger denial of service
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Affected versions
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
Fixed in
6.0.26
References
Updated Mar 02, 2025 · Source: OSV.dev | ||
6.0.22
patch
1 CVE
CVE-2025-26803
GHSA-2cj2-qqxj-5m3r
BIT-passenger-2025-26803
BIT-passenger-apache-module-2025-26803
BIT-passenger-nginx-module-2025-26803
Feb 24, 2025
Phusion Passenger denial of service
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Affected versions
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
Fixed in
6.0.26
References
Updated Mar 02, 2025 · Source: OSV.dev | ||
6.0.21
patch
1 CVE
CVE-2025-26803
GHSA-2cj2-qqxj-5m3r
BIT-passenger-2025-26803
BIT-passenger-apache-module-2025-26803
BIT-passenger-nginx-module-2025-26803
Feb 24, 2025
Phusion Passenger denial of service
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method. Affected versions
6.0.21
6.0.22
6.0.23
6.0.24
6.0.25
Fixed in
6.0.26
References
Updated Mar 02, 2025 · Source: OSV.dev | ||
6.0.20
patch
| ||
6.0.19
patch
| ||
6.0.18
patch
| ||
6.0.17
patch
| ||
6.0.16
patch
| ||
6.0.15
patch
| ||
6.0.14
patch
| ||
6.0.13
patch
| ||
6.0.12
patch
| ||
6.0.11
patch
| ||
6.0.10
patch
| ||
6.0.9
patch
| ||
6.0.8
patch
| ||
6.0.7
patch
| ||
6.0.6
patch
| ||
6.0.5
patch
| ||
6.0.4
patch
| ||
6.0.3
patch
| ||
6.0.2
patch
| ||
6.0.1
patch
| ||
6.0.0
major
| ||
5.3.7
patch
| ||
5.3.6
patch
| ||
5.3.5
patch
| ||
5.3.4
patch
| ||
5.3.3
patch
| ||
5.3.2
patch
| ||
5.3.1
patch
5 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12026
GHSA-7cv3-gvmc-8mq5
May 14, 2022
Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-12027
GHSA-whfx-877c-5p28
May 13, 2022
Insecure Permissions in Phusion Passenger
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-12028
GHSA-jjhj-8gx7-x836
May 13, 2022
Incorrect Access Control in Phusion Passenger
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.3.0
minor
5 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12026
GHSA-7cv3-gvmc-8mq5
May 14, 2022
Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-12027
GHSA-whfx-877c-5p28
May 13, 2022
Insecure Permissions in Phusion Passenger
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-12028
GHSA-jjhj-8gx7-x836
May 13, 2022
Incorrect Access Control in Phusion Passenger
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID. Affected versions
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
5.2.3
patch
2 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.2
patch
2 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.1
patch
2 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.0
minor
2 CVEs
CVE-2018-12029
GHSA-jjcj-fgfm-9g9r
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
7.0
/ 10
High
Local
High
Low
None
Unchanged
High
High
High
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation. Affected versions
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
+ 118 more Show less
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References
Updated Feb 20, 2024 · Source: OSV.dev
CVE-2018-12615
GHSA-4284-jfhc-f854
May 13, 2022
Phusion Passenger incorrect permission assignment
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges. Affected versions
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.2
+ 151 more Show less
2.1.3
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
3.0.0
3.0.0.pre1
3.0.0.pre2
3.0.0.pre3
3.0.0.pre4
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.17
3.0.18
3.0.19
3.0.2
3.0.21
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.9.1.beta
3.9.2.beta
4.0.0.rc4
4.0.0.rc6
4.0.1
4.0.10
4.0.13
4.0.14
4.0.16
4.0.17
4.0.18
4.0.19
4.0.2
4.0.20
4.0.21
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.39
4.0.4
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.46
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.7
4.0.8
5.0.0.beta1
5.0.0.beta2
5.0.0.beta3
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.10
5.0.11
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.3
5.0.30
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.3.0
5.3.1
Fixed in
5.3.2
References Updated Nov 08, 2023 · Source: OSV.dev |