Description
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.
Remediation
References
Related Vulnerabilities
WordPress Plugin Conditional Payments for WooCommerce Cross-Site Request Forgery (2.3.1)
MySQL CVE-2024-21050 Vulnerability (CVE-2024-21050)
WordPress Plugin Mobile Device Detection by 51Degrees Cross-Site Scripting (3.1.5.2)
WordPress Plugin Recipe Card Blocks for Gutenberg & Elementor Cross-Site Scripting (2.8.2)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4464)