CVE-2014-1832: Phusion Passenger

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.

Affected products

  • Phusion Passenger: up to and including 4.0.36

Published 2015-02-19. Last modified 2026-06-17.