Phusion Passenger Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2018-12027 - Vulnerability Database

Phusion Passenger Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2018-12027

High
Reference: CVE-2018-12027
Title: Phusion Passenger Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket if any of the parent directories of said socket are writable by a normal user that is not the application39s user then that non-application user can swap that directory with something else resulting in traffic being redirected to a non-application user39s process through an alternative Unix domain socket.