CVE-2017-16355

CVE-2017-16355

In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status –show=xml.

Source: CVE-2017-16355

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다