SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-12615

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2.

MEDIUM 5.3EPSS 1.20%

Does this matter?

Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.20% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
phusion/passenger
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.