High severityCISA KEVNVD Advisory· Published Mar 27, 2019· Updated Oct 21, 2025
CVE-2019-5418
CVE-2019-5418
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
actionviewRubyGems | >= 5.2.0, < 5.2.2.1 | 5.2.2.1 |
actionviewRubyGems | >= 4.0.0, < 4.2.11.1 | 4.2.11.1 |
actionviewRubyGems | >= 5.1.0, < 5.1.6.2 | 5.1.6.2 |
actionviewRubyGems | >= 5.0.0, < 5.0.7.2 | 5.0.7.2 |
Affected products
29- ghsa-coords28 versionspkg:gem/actionviewpkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/rubygem-actioncable-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actionmailbox-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actionmailer-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actionpack-5_1&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/rubygem-actionpack-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actiontext-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actionview-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activejob-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activemodel-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activerecord-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activestorage-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activesupport-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-rails-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-railties-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/rubygem-actionpack-4_2&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/rubygem-actionpack-4_2&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/rubygem-actionpack-4_2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
>= 5.2.0, < 5.2.2.1+ 27 more
- (no CPE)range: >= 5.2.0, < 5.2.2.1
- (no CPE)range: < 2.6.5-lp151.2.18.2
- (no CPE)range: < 2.6.5-lp152.2.3.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 5.1.4-lp150.2.3.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.18.1
- (no CPE)range: < 2.6.5-3.3.1
- (no CPE)range: < 2.6.5-3.18.1
- (no CPE)range: < 2.6.5-3.3.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 4.2.9-7.6.1
- (no CPE)range: < 4.2.9-7.6.1
- (no CPE)range: < 4.2.9-7.6.1
- Rails/https://github.com/rails/railsv5Range: 5.2.2.1
Patches
Vulnerability mechanics
References
22- www.exploit-db.com/exploits/46585/mitreexploitx_refsource_EXPLOIT-DB
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlghsavendor-advisoryx_refsource_SUSEWEB
- access.redhat.com/errata/RHSA-2019:0796ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1147ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1149ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1289ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-86g5-2wh3-gc9jghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/mitrevendor-advisoryx_refsource_FEDORA
- nvd.nist.gov/vuln/detail/CVE-2019-5418ghsaADVISORY
- packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.htmlghsax_refsource_MISCWEB
- www.openwall.com/lists/oss-security/2019/03/22/1ghsamailing-listx_refsource_MLISTWEB
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/ghsax_refsource_CONFIRMWEB
- lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlghsamailing-listx_refsource_MLISTWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGAghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGAghsaWEB
- web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-releasedghsaWEB
- weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-releasedghsaWEB
- weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/mitrex_refsource_CONFIRM
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
- www.exploit-db.com/exploits/46585ghsaWEB
News mentions
0No linked articles in our index yet.