CVE-2019-5418
27.03.2019, 14:29
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
| Vendor | Product | Version |
|---|---|---|
| rubyonrails | rails | 3.0.0 ≤ 𝑥 < 4.2.11.1 |
| rubyonrails | rails | 5.0.0 ≤ 𝑥 < 5.0.7.2 |
| rubyonrails | rails | 5.1.0 ≤ 𝑥 < 5.1.6.2 |
| rubyonrails | rails | 5.2.0 ≤ 𝑥 < 5.2.2.1 |
| debian | debian_linux | 8.0 |
| redhat | cloudforms | 4.7 |
| opensuse | leap | 15.0 |
| redhat | cloudforms | 4.6 |
| redhat | software_collections | 1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rails |
| ||||||||||||||||||||||||||||||
| rails-4.0 |
| ||||||||||||||||||||||||||||||
| ruby-actionpack-3.2 |
| ||||||||||||||||||||||||||||||
| ruby-activemodel-3.2 |
| ||||||||||||||||||||||||||||||
| ruby-activerecord-3.2 |
| ||||||||||||||||||||||||||||||
| ruby-activesupport-3.2 |
| ||||||||||||||||||||||||||||||
| ruby-rails-3.2 |
|
References