In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
{
"cpe": "cpe:2.3:a:phusion:passenger:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.0.30"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}