Passenger

Vendor:

First CVE: Sep 30, 2013 · Active for 12 years

13
Total CVEs
More Total CVEs than 91% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Passenger over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2013
12 years ago
Most Recent CVE
Feb 24, 2025
516 days ago

CVE Severity & Scoring

Passenger13 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local4 (30.8%)
Network5 (38.5%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (53.8%)
High2 (15.4%)
Unknown4 (30.8%)
User Interaction
None8 (61.5%)
Unknown4 (30.8%)
Required1 (7.7%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None5 (38.5%)
Unknown4 (30.8%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories i
Jun 17, 20189.829NONO
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned app
Jun 17, 20188.826NONO
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the p
Apr 18, 20177.826NONO
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Nov 19, 20197.524NONO
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to
Jun 17, 20187.824NONO
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
Feb 24, 20257.522NONO
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir wit
Jun 17, 20187.022NONO
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to
Jun 21, 20185.319NONO
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a
Jan 3, 20144.619NONO
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is poss
Dec 14, 20174.718NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Passenger

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.424.50.4%00
4.0.324.50.4%00
4.0.224.50.4%00
4.0.124.50.4%00
4.0.017.52.3%00
3.0.914.60.4%00
3.0.814.60.4%00
3.0.714.60.4%00
3.0.614.60.4%00
3.0.514.60.4%00
3.0.414.60.4%00
3.0.314.60.4%00
3.0.214.60.4%00
3.0.1914.60.4%00
3.0.1814.60.4%00
3.0.1714.60.4%00
3.0.1514.60.4%00
3.0.1414.60.4%00
3.0.1314.60.4%00
3.0.1214.60.4%00