Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-7519

13
FAUCET Score

CVE-2015-7519 describes a header spoofing vulnerability in Phusion Passenger versions prior to 4.0.60 and 5.0.22, affecting Apache integration and standalone modes without a filtering proxy. Attackers can manipulate HTTP headers by substituting underscores for dashes, potentially leading to unauthorized actions within applications. The vulnerability has a CVSSv3 score of 3.7 (Low), indicating a network-based attack with high complexity and a low impact on integrity, with no impact on confidentiality or availability. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.0.59CPE matchmatch criteria
cpe:2.3:a:phusionpassenger:phusion_passenger:*:*:*:*:*:*:*:*
5.0.0CPE matchmatch criteria
cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:*:*:*:*:*:*:*
5.0.0CPE matchmatch criteria
cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta1:*:*:*:*:*:*
5.0.0CPE matchmatch criteria
cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta2:*:*:*:*:*:*
5.0.0CPE matchmatch criteria
cpe:2.3:a:phusionpassenger:phusion_passenger:5.0.0:beta3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

3.7LOW

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.36%
Probability of exploitation in next 30 days
EPSS Percentile
82.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0236 is in the 79th percentile among its peer group of 1,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

rubygemspatch availablevia ghsa
Product: passengerFixed in: 4.0.60
rubygemspatch availablevia ghsa
Product: passengerFixed in: 5.0.22
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-passenger40-passenger
redhatend of lifevia redhat_api
Product: OpenStack ForemanFixed in: ruby193-rubygem-passenger
redhatend of lifevia redhat_api
Product: OpenStack ForemanFixed in: rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 1.3Fixed in: ruby193-rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 1.3Fixed in: rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerFixed in: ruby193-rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerFixed in: rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: ruby193-rubygem-passenger
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: ruby200-rubygem-passenger

Vendor Advisories (2)

rubygemsGHSA-fxwv-953p-7qpflow

Phusion Passenger allows remote attackers to spoof headers

Oct 10, 2018
redhatCVE-2015-7519Moderate

passenger: Header overwriting issue allowing user impersonation

Dec 7, 2015

References

lists.opensuse.org / opensuse-security-announce/2015-12/msg00024.html
blog.phusion.nl / 2015/12/07/cve-2015-7519
Vendor Advisory
bugzilla.suse.com / show_bug.cgi
github.com / phusion/passenger/commit/ddb8ecc4ebf260e4967f57f271d4f5761abeac3e
lists.debian.org / debian-lts-announce/2018/06/msg00007.html
puppet.com / security/cve/passenger-dec-2015-security-fixes
openwall.com / lists/oss-security/2015/12/07/1
openwall.com / lists/oss-security/2015/12/07/2