Vulnerabilities > Phusion > Passenger > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-17 CVE-2018-12026 Link Following vulnerability in Phusion Passenger 5.3.0/5.3.1
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks.
network
low complexity
phusion CWE-59
7.5