High severityCISA KEVNVD Advisory· Published Mar 27, 2019· Updated Oct 21, 2025
CVE-2019-5418
CVE-2019-5418
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
actionviewRubyGems | >= 5.2.0, < 5.2.2.1 | 5.2.2.1 |
actionviewRubyGems | >= 4.0.0, < 4.2.11.1 | 4.2.11.1 |
actionviewRubyGems | >= 5.1.0, < 5.1.6.2 | 5.1.6.2 |
actionviewRubyGems | >= 5.0.0, < 5.0.7.2 | 5.0.7.2 |
Affected products
1- Rails/https://github.com/rails/railsv5Range: 5.2.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- www.exploit-db.com/exploits/46585/mitreexploitx_refsource_EXPLOIT-DB
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.htmlghsavendor-advisoryx_refsource_SUSEWEB
- access.redhat.com/errata/RHSA-2019:0796ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1147ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1149ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:1289ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-86g5-2wh3-gc9jghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/mitrevendor-advisoryx_refsource_FEDORA
- nvd.nist.gov/vuln/detail/CVE-2019-5418ghsaADVISORY
- packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.htmlghsax_refsource_MISCWEB
- www.openwall.com/lists/oss-security/2019/03/22/1ghsamailing-listx_refsource_MLISTWEB
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/ghsax_refsource_CONFIRMWEB
- lists.debian.org/debian-lts-announce/2019/03/msg00042.htmlghsamailing-listx_refsource_MLISTWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGAghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGAghsaWEB
- web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-releasedghsaWEB
- weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-releasedghsaWEB
- weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/mitrex_refsource_CONFIRM
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
- www.exploit-db.com/exploits/46585ghsaWEB
News mentions
0No linked articles in our index yet.