First published: Tue Nov 19 2019(Updated: )
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ruby-passenger | ||
Phusion Passenger Ruby | =4.0.0-beta1 | |
Phusion Passenger Ruby | =4.0.0-beta2 | |
Redhat Openshift | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-6135 is high with a CVSS score of 7.5.
The affected software for CVE-2012-6135 includes RubyGems passenger 4.0.0 betas 1 and 2, as well as IBM Robotic Process Automation as a Service.
Remote attackers can exploit CVE-2012-6135 to delete arbitrary files during the startup process.
There is no specific fix available for CVE-2012-6135, but it is recommended to update to a newer version of RubyGems passenger or apply any available patches.