CVE-2014-1831

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/02/2015
Last modified:
12/04/2025

Description

Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phusion:passenger:*:*:*:*:*:*:*:* 4.0.36 (including)