Description
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4999)
WordPress 6.4.x Multiple Vulnerabilities (6.4 - 6.4.2)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31545)
Joomla! Core Multiple Vulnerabilities (2.5.0 - 3.9.2)
Perl Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-1238)