CyberSec.Space Logo
Back to CVE Browser

CVE-2019-5418

Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
EPSS Score36.7910%
EPSS Percentile90.11th
PublishedMar 27, 2019
Last ModifiedOct 30, 2025

Vulnerability Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Affected Platforms (CPE)

πŸ“¦
Rubyonrails

Rails

>= 3.0.0 and < 4.2.11.1
πŸ“¦
Rubyonrails

Rails

>= 5.0.0 and < 5.0.7.2
πŸ“¦
Rubyonrails

Rails

>= 5.1.0 and < 5.1.6.2
πŸ“¦
Rubyonrails

Rails

>= 5.2.0 and < 5.2.2.1
πŸ’»
Debian

Debian Linux

= 8.0
πŸ“¦
Redhat

Cloudforms

= 4.7
πŸ’»
Opensuse

Leap

= 15.0
πŸ’»
Fedoraproject

Fedora

= 30
πŸ“¦
Redhat

Cloudforms

= 4.6
πŸ“¦
Redhat

Software Collections

= 1.0

References & Advisories

Related Vulnerabilities