CVE-2016-10345

HIGH7.8EPSS 0.06%

Phusion Passenger uses a known /tmp filename

發布日:2018/8/21修改日:2026/4/28
也稱為:GHSA-cqxw-3p7v-p9grDEBIAN-CVE-2016-10345

描述

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(8)