HIGH
passenger: Improper access control in SpawningKit can allow malicious child processes to kill arbitrary processes
Published Jun 17, 2018
7.8
HIGHCVSS 3.0
EPSS 0.90%
Description
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.
Affected products
No data.
No data.
Red Hat Ceph Storage 1.3
rubygem-passenger
Not affected
Red Hat Satellite 6
rubygem-passenger
Not affected
Red Hat Update Infrastructure 3 for Cloud Providers
rubygem-passenger
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 1.3 | rubygem-passenger | Not affected | n/a |
| Red Hat Satellite 6 | rubygem-passenger | Not affected | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | rubygem-passenger | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://access.redhat.com/security/cve/CVE-2018-12028 Vendor Advisory
- https://blog.phusion.nl/passenger-5-3-2 x_refsource_MISCMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1592621 Issue Tracking
- https://github.com/advisories/GHSA-jjhj-8gx7-x836 Advisory
- https://github.com/phusion/passenger/commit/1e7c82deb4901c438f583737d8c9f2aac264737c
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2018-12028.yml
- https://nvd.nist.gov/vuln/detail/CVE-2018-12028
- https://security.gentoo.org/glsa/201807-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12028
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-12028 | Vendor Advisory | |
| https://blog.phusion.nl/passenger-5-3-2 | x_refsource_MISCMitigationVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1592621 | Issue Tracking | |
| https://github.com/advisories/GHSA-jjhj-8gx7-x836 | Advisory | |
| https://github.com/phusion/passenger/commit/1e7c82deb4901c438f583737d8c9f2aac264737c | ||
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/passenger/CVE-2018-12028.yml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-12028 | ||
| https://security.gentoo.org/glsa/201807-02 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-12028 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 17, 2018
Updated Aug 5, 2024
Reserved Jun 7, 2018
Link CVE-2018-12028
CISA Vulnrichment
GHSA-JJHJ-8GX7-X836 Updated n/a