Insecure Permissions in Phusion Passenger
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jun 28, 2023
Description
Published by the National Vulnerability Database
Jun 17, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 9, 2023
Last updated
Jun 28, 2023
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.
References