Description
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
Remediation
References
Related Vulnerabilities
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19926)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4226)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11585)
Drupal Improper Input Validation Vulnerability (CVE-2016-9452)