CVE-2015-7519 describes a header spoofing vulnerability in Phusion Passenger versions prior to 4.0.60 and 5.0.22, affecting Apache integration and standalone modes without a filtering proxy. Attackers can manipulate HTTP headers by substituting underscores for dashes, potentially leading to unauthorized actions within applications. The vulnerability has a CVSSv3 score of 3.7 (Low), indicating a network-based attack with high complexity and a low impact on integrity, with no impact on confidentiality or availability. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.59CPE matchmatch criteria | cpe:2.3:a:phusionpassenger:phusion_passenger:*:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta1:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta2:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.