VendorsPhusionpassenger4.0.4
Vulnerabilities

Phusion Passenger 4.0.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-2119
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
Published 2014-01-02 · Modified
4.6EPSS 0.004
CVE-2013-4136
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
Published 2013-09-30 · Modified
4.4EPSS 0.003