CVE-2017-16355: Infoleak
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-16355.
What software versions are affected by this vulnerability?
Phusion Passenger 5.1.10, Passenger Open Source 5.1.11, and Passenger Enterprise 5.1.10 are affected by this vulnerability.
How can the contents of arbitrary files be listed with this vulnerability?
By symlinking a file named REVISION from the application root, it is possible to list the contents of arbitrary files on a system.
What is the severity rating of this vulnerability?
This vulnerability has a severity rating of medium with a value of 4.7.
How can I fix this vulnerability?
To fix this vulnerability, upgrade to Passenger Open Source 5.1.11 or Passenger Enterprise 5.1.10.