Back to Database
Status published
Unknown
CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View...
Vulnerability Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-5418
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/46585/
- http://packetstormsecurity.com/files/152178/Rails-5.2.1-Arbitrary-File-Content-Disclosure.html
- http://www.openwall.com/lists/oss-security/2019/03/22/1
- https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/
- https://groups.google.com/forum/#%21topic/rubyonrails-security/pFRKI96Sm8Q
- https://lists.debian.org/debian-lts-announce/2019/03/msg00042.html
- https://access.redhat.com/errata/RHSA-2019:0796
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/
- https://access.redhat.com/errata/RHSA-2019:1149
- https://access.redhat.com/errata/RHSA-2019:1147
- https://access.redhat.com/errata/RHSA-2019:1289
More from Rails
View All →CVE-2025-24293
# Active Storage allowed transformation methods potentially unsafe
Active Storage attempts...
Critical
9.2
CVE-2023-38037
ActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file....
Medium
5.5
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain...
Unknown
0
CVE-2023-28120
There is a vulnerability in ActiveSupport if the new bytesplice...
Unknown
0
CVE-2023-27539
There is a denial of service vulnerability in the header...
Unknown
0
Affected Vendor
Rails
View all reports →Affected Software
https://github.com/rails/rails
Vulnerable Versions:
5.2.2.1, 5.1.6.2, 5.0.7.2, 4.2.11.1
Timeline
Official Publish:
March 27th, 2019
Last Modified:
October 21st, 2025
Added to House:
July 20th, 2026
CVSS Vectors
No vector data available