AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12028

HIGH · CVSS 7.8 EPSS 0.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-12028
Severity
HIGH
CVSS
7.8
EPSS
0.90%

Original NVD Description

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.