Known Vulnerabilities for products from Phusion
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Phusion".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-12615 json | An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of... | 5.3 - MEDIUM | 2018-06-21 | 2019-10-03 |
| CVE-2018-12029 json | A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges ... | 7 - HIGH | 2018-06-17 | 2019-03-08 |
| CVE-2018-12028 json | An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed m... | 7.8 - HIGH | 2018-06-17 | 2019-10-03 |
| CVE-2018-12027 json | An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in... | 8.8 - HIGH | 2018-06-17 | 2019-10-03 |
| CVE-2018-12026 json | During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows ... | 9.8 - CRITICAL | 2018-06-17 | 2019-03-08 |
| CVE-2017-16355 json | In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterpri... | Not Provided | 2017-12-14 | 2025-04-20 |
| CVE-2016-10345 json | In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which coul... | Not Provided | 2017-04-18 | 2025-04-20 |
| CVE-2014-1832 json | Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_pro... | Not Provided | 2015-02-19 | 2026-05-06 |
| CVE-2014-1831 json | Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) cont... | Not Provided | 2015-02-19 | 2026-05-06 |
| CVE-2013-7134 json | Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging ... | Not Provided | 2014-04-29 | 2026-05-06 |
| CVE-2013-4136 json | ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possib... | Not Provided | 2013-09-30 | 2026-04-29 |
| CVE-2013-2119 json | Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent ... | Not Provided | 2014-01-03 | 2026-04-29 |
| CVE-2012-6135 json | RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. | 7.5 - HIGH | 2019-11-19 | 2019-11-21 |