Security readout for executives and security teams
Plain-English summary
This is a local privilege-escalation issue in Phusion Passenger before 5.1.0. During passenger-install-nginx-module execution, Passenger used a predictable temporary filename in /tmp, which could let a local attacker gain the privileges of the passenger user. It is not described as a remote web attack.
Executive priority
Treat this as a targeted local privilege risk, not a broad internet-facing emergency. Prioritize older Passenger deployments on shared systems, build hosts, or servers where non-administrators have shell access.
Technical view
CVE-2016-10345 concerns a known /tmp filename used by passenger-install-nginx-module in Phusion Passenger before 5.1.0. The public description states local attackers could gain passenger-user privileges. The bundle provides no CVSS vector, CWE, CPE, or detailed affected package matrix.
Likely exposure
Exposure is most likely on systems running Phusion Passenger before 5.1.0 where passenger-install-nginx-module is executed on a host with untrusted local users or shared temporary directories.
Exploitation context
The source bundle does not show active exploitation, and KEV is false. The described prerequisite is local attacker access during the vulnerable installer/module workflow, not unauthenticated remote access.
Researcher notes
Evidence is limited to the CVE description, upstream commit, and changelog references. No exploit status, CVSS score, CWE, CPE, or operational detection detail is provided in the bundle. Do not assume broader affected products beyond Phusion Passenger before 5.1.0.
Mitigation direction
- Upgrade Phusion Passenger to 5.1.0 or later where applicable.
- Review the Phusion Passenger changelog and commit for vendor-specific remediation details.
- Restrict local shell access on systems running Passenger installation workflows.
- Avoid running passenger-install-nginx-module on shared hosts with untrusted local users.
- Check vendor guidance if packaged Passenger versions are backported by your distribution.
Validation and detection
- Inventory hosts and containers running Phusion Passenger.
- Confirm installed Passenger versions are not before 5.1.0.
- Identify whether passenger-install-nginx-module is used in build or deployment workflows.
- Review who has local access to affected hosts during installation activity.
- Check distribution package notes for backported fixes if version strings differ.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2016-10345 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/phusion/passenger/commit/e5b4b0824d6b648525b4bf63d9fa37e5beeae441CVE reference · x_refsource_CONFIRM
- https://github.com/phusion/passenger/blob/stable-5.1/CHANGELOGCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
