یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
کم اولویت 18/100

Security: Privilege Escalation via Phusion Passenger's Watchdog API

Local privilege escalation is possible.

انتشار: 2026-08-13 15:37 آخرین مشاهده داده: 2026-08-24 16:12 1 منبع · 1 رسمیاعتماد متوسط · 53/100
اولویت VulnWatch 18/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS — / — شدت فنی / احتمال بهره‌برداری
کیفیت داده 56/100 نیازمند توجه · اعتماد متوسط
تازگی داده قدیمی قدیمی‌تر از ۳۰ روز · 1 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
کیفیت داده 56/100نیازمند توجه · 1 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار در این صفحه ثبت شده است؛ بخش راهکار پیشنهادی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority13
راهکار اجرایی موجود
01

خلاصه آسیب‌پذیری

Local privilege escalation is possible.
02

توضیحات کامل

Situation A security vulnerability has been discovered in Phusion Passenger's Watchdog API. Note: This does not affect default installations of cPanel. This vulnerability is only applicable to servers where an affected package has been installed. Please check the "Affected Product Versions" Table for a full list of vulnerable packages. Affected Product Versions Product Affected Versions Patched Versions cPanel/WHM All versions with one of the following packages installed: ea-apache24-mod-passenger ea-passenger-src ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger ea-nginx-passenger ea-apache24-mod-passenger: 6.1.8-2 ea-passenger-src: 6.1.8-2 ea-ruby27-rubygem-passenger: 6.0.27-2 (el7), 6.1.8-2 (el8) ea-ruby27-mod_passenger: 6.0.27-2 (el7), 6.1.8-2 (el8) ea-ruby24-rubygem-passenger: 6.0.20-4 ea-ruby24-mod_passenger: 6.0.20-4 ea-nginx-passenger: 6.1.8-2 Impact Local privilege escalation is possible. Call to action Note: CloudLinux engineering is currently preparing and testing patched packages. This page will be updated once those packages are available for CloudLinux systems. Make sure the Passenger packages are updated to the latest version. The following command can be used to update all packages: # /scripts/update-packages Alternatively, the following commands can be used to update those individual packages as needed. These commands will only update packages that are already installed on the server: CentOS 7/CloudLinux 7 # yum update ea-apache24-mod-passenger ea-nginx-passenger ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger AlmaLinux/CloudLinux 8/9/10 # dnf update ea-apache24-mod-passenger ea-nginx-passenger ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger Ubuntu # apt update && apt install --only-upgrade ea-apache24-mod-passenger If Passenger was installed and reachable on your server before it was patched, the following command can be used to check for signs of compromise: CPANEL_WARN: Please note that a clean result does not confirm a server was not exploited as these entries are not written at the default log level. Unless the log level has already been raised on your server these would not be recorded. # grep -E 'API account database is empty|Authentication failed for UID' /etc/apache2/logs/error_log /usr/local/apache/logs/error_log 2>/dev/null The log level can be raised if needed to capture any future attempts via the following steps: Log in to WHM as the root user, and access Home / Service Configuration / Apache Configuration / Include Editor Under the Pre Main Include section, select All Versions from the drop-down add the following: CONFIG_TEXT: PassengerLogLevel 4 Click the Update button to save the configuration, and the Restart Apache button on the next page to restart the service. How to verify that a server is patched The following commands can be used to confirm the currently installed version of the Passenger packages: CentOS/AlmaLinux/CloudLinux # rpm -q ea-apache24-mod-passenger ea-passenger-src ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger ea-nginx-passenger Ubuntu # dpkg-query -W -f='${Package} ${Version}\n' ea-apache24-mod-passenger ea-passenger-src ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger ea-nginx-passenger
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
Note: CloudLinux engineering is currently preparing and testing patched packages. This page will be updated once those packages are available for CloudLinux systems. Make sure the Passenger packages are updated to the latest version. The following command can be used to update all packages: # /scripts/update-packages Alternatively, the following commands can be used to update those individual packages as needed. These commands will only update packages that are already installed on the server:
این دستورها از اطلاعات منبع ثبت‌شده استخراج شده‌اند. پیش از اجرا، منبع اصلی، نسخه محصول و شرایط محیط خود را بررسی کنید.
دستور رسمی 1
cPanel Support Security · رسمی · BASH
# /scripts/update-packages
مشاهده منبع ↗
دستور رسمی 2
cPanel Support Security · رسمی · BASH
# yum update ea-apache24-mod-passenger ea-nginx-passenger ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger
مشاهده منبع ↗
دستور رسمی 3
cPanel Support Security · رسمی · BASH
# dnf update ea-apache24-mod-passenger ea-nginx-passenger ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger
مشاهده منبع ↗
دستور رسمی 4
cPanel Support Security · رسمی · BASH
# apt update && apt install --only-upgrade ea-apache24-mod-passenger
مشاهده منبع ↗
دستور رسمی 5
cPanel Support Security · رسمی · BASH
# grep -E 'API account database is empty|Authentication failed for UID'  /etc/apache2/logs/error_log /usr/local/apache/logs/error_log 2>/dev/null
مشاهده منبع ↗
دستور رسمی 6
cPanel Support Security · رسمی · BASH
# rpm -q ea-apache24-mod-passenger ea-passenger-src ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger ea-nginx-passenger
مشاهده منبع ↗
دستور رسمی 7
cPanel Support Security · رسمی · BASH
# dpkg-query -W -f='${Package} ${Version}\n' ea-apache24-mod-passenger ea-passenger-src ea-ruby27-rubygem-passenger ea-ruby27-mod_passenger ea-ruby24-rubygem-passenger ea-ruby24-mod_passenger ea-nginx-passenger
مشاهده منبع ↗
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
53/100
اعتماد متوسط اعتماد داده 56/100 نیازمند توجه داده قدیمی وضعیت تازگی قدیمی‌تر از ۳۰ روز تازگی مشاهده 75/100 کامل‌بودن · مناسب 52/100 پوشش منابع 1 منبع مرتبط 1 رسمی · 1 سطح ۱ 0 اختلاف بین منابع 2 خلأ کیفیت
cPanel Support Security رسمی
CVSS
—
شدت
low
محصول
cPanel / cPanel & WHM
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2026-08-13
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
توضیحات 1 منبع
cPanel Support Securityرسمی
Situation A security vulnerability has been discovered in Phusion Passenger's Watchdog API. Note: This does not affect default installations of cPanel. This vulnerability is only applicable to servers where an affected package has been installed. Please check the "Affected Product Versions" Table for a full list of vulnerable packages.   Affected Product Versions Product Affected Versions Patched...
منبع ↗
اثر 1 منبع
cPanel Support Securityرسمی
Local privilege escalation is possible.
منبع ↗
راهکار 1 منبع
cPanel Support Securityرسمی
Make sure the Passenger packages are updated to the latest version. The following command can be used to update all packages: # /scripts/update-packages Alternatively, the following commands can be used to update those individual packages as needed. These commands will only update packages that are already installed on the server:
منبع ↗
شدت 1 منبع
cPanel Support Securityرسمی
low
منبع ↗
خلاصه 1 منبع
cPanel Support Securityرسمی
Local privilege escalation is possible.
منبع ↗
عنوان 1 منبع
cPanel Support Securityرسمی
Security: Privilege Escalation via Phusion Passenger's Watchdog API
منبع ↗
↗