VYPR
High severityCISA KEVNVD Advisory· Published Mar 27, 2019· Updated Oct 21, 2025

CVE-2019-5418

CVE-2019-5418

Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
actionviewRubyGems
>= 5.2.0, < 5.2.2.15.2.2.1
actionviewRubyGems
>= 4.0.0, < 4.2.11.14.2.11.1
actionviewRubyGems
>= 5.1.0, < 5.1.6.25.1.6.2
actionviewRubyGems
>= 5.0.0, < 5.0.7.25.0.7.2

Affected products

1
  • Rails/https://github.com/rails/railsv5
    Range: 5.2.2.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

22

News mentions

0

No linked articles in our index yet.