UNKNOWN RubyGems

insecure temporary directory usage in passenger

GHSA-w6rc-q387-vpgq · CVE-2013-4136

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

Ready to move

Start Securing

Free, no credit card | First findings in minutes