LiveActive security incident?Get immediate response
CVE Record

CVE-2016-10345: In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module exe...

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a local privilege-escalation issue in Phusion Passenger before 5.1.0. During passenger-install-nginx-module execution, Passenger used a predictable temporary filename in /tmp, which could let a local attacker gain the privileges of the passenger user. It is not described as a remote web attack.

Executive priority

Treat this as a targeted local privilege risk, not a broad internet-facing emergency. Prioritize older Passenger deployments on shared systems, build hosts, or servers where non-administrators have shell access.

Technical view

CVE-2016-10345 concerns a known /tmp filename used by passenger-install-nginx-module in Phusion Passenger before 5.1.0. The public description states local attackers could gain passenger-user privileges. The bundle provides no CVSS vector, CWE, CPE, or detailed affected package matrix.

Likely exposure

Exposure is most likely on systems running Phusion Passenger before 5.1.0 where passenger-install-nginx-module is executed on a host with untrusted local users or shared temporary directories.

Exploitation context

The source bundle does not show active exploitation, and KEV is false. The described prerequisite is local attacker access during the vulnerable installer/module workflow, not unauthenticated remote access.

Researcher notes

Evidence is limited to the CVE description, upstream commit, and changelog references. No exploit status, CVSS score, CWE, CPE, or operational detection detail is provided in the bundle. Do not assume broader affected products beyond Phusion Passenger before 5.1.0.

Mitigation direction

  • Upgrade Phusion Passenger to 5.1.0 or later where applicable.
  • Review the Phusion Passenger changelog and commit for vendor-specific remediation details.
  • Restrict local shell access on systems running Passenger installation workflows.
  • Avoid running passenger-install-nginx-module on shared hosts with untrusted local users.
  • Check vendor guidance if packaged Passenger versions are backported by your distribution.

Validation and detection

  • Inventory hosts and containers running Phusion Passenger.
  • Confirm installed Passenger versions are not before 5.1.0.
  • Identify whether passenger-install-nginx-module is used in build or deployment workflows.
  • Review who has local access to affected hosts during installation activity.
  • Check distribution package notes for backported fixes if version strings differ.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2016-10345 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.