In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| passenger(RubyGems) | 0 | 5.1.0 | N/A |
CVSS Metrics