{"id":"CVE-2018-12027","details":"An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.","aliases":["GHSA-whfx-877c-5p28"],"modified":"2026-07-08T14:14:10.174281Z","published":"2018-06-17T20:29:00.417Z","references":[{"type":"ADVISORY","url":"https://blog.phusion.nl/passenger-5-3-2"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201807-02"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phusion/passenger","events":[{"introduced":"a53aa1fb31489cd27c5c34f059ed2c90ddca012b"},{"fixed":"5e4d60575fadfd68913bd229990cb9f3feb393a9"}],"database_specific":{"extracted_events":[{"introduced":"5.3.0"},{"fixed":"5.3.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:phusion:passenger:*:*:*:*:*:*:*:*"}}],"versions":["release-5.3.1","release-5.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12027.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}